What is CVE-2026-64951?
CVE-2026-64951 is a vulnerability in the Velociraptor server where a rogue client can upload a malformed sparse file, causing a divide-by-zero panic in the ShouldPadFile() function when the GUI attempts expansion, potentially crashing the server process. Affected users should restrict GUI access and monitor for anomalies.
Azərbaycanca: CVE-2026-64951 zəifliyi Velociraptor serverində aşkarlanıb: zərərli müştəri xüsusi hazırlanmış sparse fayl yükləyərək GUI-nin ShouldPadFile() funksiyasında sıfıra bölmə xətasına səbəb olur, bu da server prosesinin çökməsinə gətirir. Təsirə məruz qalan istifadəçilər server GUI-ni məhdudlaşdırmalı və anomaliyaları izləməlidir.
FAQ2
Which server software is affected by the CVE-2026-64951 vulnerability?
This vulnerability affects the Velociraptor server.
How is the CVE-2026-64951 vulnerability exploited?
A rogue client uploads a malformed sparse file, causing a divide-by-zero panic in the ShouldPadFile() function of the GUI.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.