GHSA-7xqm-7738-642x · Severity: high · Ecosystem: go — File Browser's Uncontrolled Memory Consumption vulnerability can enable DoS attack due to oversized file processing
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.38.0, a Denial of Service (DoS) vulnerability exists in the file processing logic when reading a file on endpoint `Filebrowser-Server-IP:PORT/files/{file-name}` . While the server correctly handles and stores uploaded files, it attempts to load the entire content into memory during read operations without size checks or resource limits. This allows an authenticated user to upload a large file and trigger uncontrolled memory consumption on read, potentially crashing the server and making it unresponsive. As of time of publication, no known patches are available.
Conclusion & alert: CVE-2025-53893 is rated High Exploit Risk (73/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.91%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-11 | 0.27% | 0.91% | +0.64% |
| 2 | 2026-02-08 | 0.21% | 0.27% | +0.06% |
| 3 | 2025-12-12 | — | 0.21% | — |
Full EPSS history (7 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.7 | 4.0 | HIGH |
|
— | — | [email protected] |
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
GHSA-7xqm-7738-642x · Severity: high · Ecosystem: go — File Browser's Uncontrolled Memory Consumption vulnerability can enable DoS attack due to oversized file processing
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| filebrowser | filebrowser | 2.38.0 | cpe:2.3:a:filebrowser:filebrowser:2.38.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/filebrowser/filebrowser/issues/5294 | Issue Tracking |
| https://github.com/filebrowser/filebrowser/security/advisories/GHSA-7xqm-7738-642x | Exploit Vendor Advisory |