CVE-2026-86776

NameCVE-2026-86776
DescriptionKeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Notes

Bogus CVE for keepass2:
Quoting from https://keepass.info/help/kb/sec_issues.html:
When reading a KDBX file, KeePass may allocate about 2 GB of RAM (temporarily).
We do not consider this to be a problem. Especially, it is not a security issue.

Search for package or bug name: Reporting problems