CVE-2026-77633

HIGH CVSS 3.1: 7.1 EPSS 0.37%
Updated Sep 26, 2026
Cloudreve
Parameter Value
CVSS 7.1 (HIGH)
Fixed In 4.18.0
Type CWE-770 (Allocation Without Limits), CWE-367 (Time-of-check Time-of-use (TOCTOU)), CWE-362 (Race Condition)
Vendor Cloudreve
Public PoC No

Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs/upload.go checks a stale in-memory user storage value through validateUserCapacity and later applies an unconditional storage charge outside the same quota-enforcing transaction. An authenticated user with Files.Write permission can issue concurrent upload-session requests that read the same capacity snapshot, all pass the MaxStorage check, and reserve their declared sizes through CommitWithStorageDiff.

The resulting reservations can exceed the account quota and can be materialized as chunked uploads that exhaust host storage and deny uploads to other users. The default local-storage policy and default User group are affected. This issue is fixed in version 4.18.0.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
High
Complete denial of service

CVSS Vector v3.1