CVE-2026-6684
FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded loop count derived from GPT header field
CVSS
4.6
Medio
EPSS
0.3%
p23
KEV
—
Exploit Today
7
0-100
Publicado: 1 jul 2026 · Última mod.: 2 jul 2026 · CWE-835
0.3%EPSS · 30 días0.4%
2026-08-132026-09-09
FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded loop count derived from GPT header field GPTH_PtNum, enabling extremely long or effectively infinite mount-time scans. This maps to CWE-835 (Loop with Unreachable Exit Condition). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (4.6, Medium). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial.
- elm-chan.orghttps://elm-chan.org/fsw/ff/
- github.comhttps://github.com/runZeroInc/vulns-2026-fatfs-chance
- www.runzero.comhttps://www.runzero.com/advisories/fatfs-gpt-scan-loop-dos-cve-2026-6684/
- www.runzero.comhttps://www.runzero.com/blog/fatfs-bugs/
- github.comhttps://github.com/runZeroInc/vulns-2026-fatfs-chance
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-781327.5 ALT—
———strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.5hCVE-2026-781295.9 MED—
———strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.5hCVE-2026-890454.0 MED—
———zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops. Attackers can pass negative length values to cause the read method to spin indefinitely while holding the stream monitor, blocking all other threads from accessing the stream.12hCVE-2026-880026.5 MED—
———Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.1, the message-chain reconstruction helper in backend/open_webui/utils/misc.py advanced through a chat history by map key but tracked visited entries using each message body's optional id field. An authenticated user could store id-less messages in a parent cycle and trigger a non-terminating walk that blocked the async event loop, grew memory until termination, and remained persistent across process restarts. This issue is fixed in version 0.11.1.17hCVE-2026-880006.5 MED—
———Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/chats/{id}/messages/{message_id} used the chat-history deletion helper in backend/open_webui/models/chats.py to follow childrenIds without recording visited message identifiers. An authenticated user could store a cyclic chat tree and delete a message, causing a synchronous infinite loop on the server request loop that blocked every user's requests until the process was killed. This issue is fixed in version 0.11.1.13hCVE-2026-870134.3 MED—
———Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /api/v1/folders/{id}/update/parent allowed a user to place a folder under itself or one of its descendants, while the folder tree walks used by DELETE /api/v1/folders/{id} and POST /api/v1/folders/{id}/read did not track visited folder identifiers. An authenticated user could persist a parent cycle and start a request that consumed CPU and memory indefinitely, with the condition remaining stored until repaired. This issue is fixed in version 0.11.1.15h