CVE-2026-86776 Details
Description
KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.
A memory exhaustion vulnerability has been identified in KeePass versions 2.35 through 2.61.1. The issue arises because the application fails to properly validate the sizes of KDBX header fields before allocating memory in the ReadHeaderField function. This oversight allows attackers to create malicious KDBX files that declare excessively long header field lengths, leading to the allocation of gigabytes of memory. As a result, the application consumes excessive resources and may terminate unexpectedly.
Users can update to KeePass version 2.61.1, which is available for download on the KeePass official website and through the KeePass 2.61.1 MSI Package via the Microsoft Windows Update Catalog.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 9, 2026CISA-ADP
Assessed Sep 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-789 | Memory Allocation with Excessive Size Value | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| KeePass | >= 2.35, <= 2.61.1 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 10, 2026 | CVE Modified | CISA-ADP |
| Sep 9, 2026 | New CVE Received | [email protected] |
Volerion