NONE · 0

CVE-2026-72813

actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the pro...

Vulnerability Description

actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the process on-demand by sending a GET request with an empty Range header.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-72813?

CVE-2026-72813 is a documented vulnerability. actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the pro...

How severe is CVE-2026-72813?

CVSS scoring is not yet available for CVE-2026-72813. Check NVD for updates.

Is there a patch for CVE-2026-72813?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.