What is CVE-2026-72813?
CVE-2026-72813 is a denial of service (DoS) vulnerability in actix-files versions before 0.6.10, triggered by an empty 'Range' header in GET requests for static files. When 'panic' is set to 'abort', remote attackers can crash the server process on-demand. Users should upgrade to version 0.6.10 or later.
Azərbaycanca: CVE-2026-72813 actix-files kitabxanasının 0.6.10-dan əvvəlki versiyalarında boş 'Range' başlığı ilə göndərilən GET sorğuları nəticəsində yaranan denial of service (DoS) zəifliyidir. Bu, uzaqdan hücum edənə, 'panic' ayarı 'abort' olaraq təyin edildikdə server prosesini çökdürməyə imkan verir. İstifadəçilərə actix-files kitabxanasını ən azı 0.6.10 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
How is CVE-2026-72813 exploited in the actix-files library?
The vulnerability is exploited by sending GET requests with an empty 'Range' header for static files. When 'panic' is set to 'abort', remote attackers can crash the server process.
What is the recommended mitigation for CVE-2026-72813?
Users are advised to upgrade the actix-files library to version 0.6.10 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.