CVE-2026-86776

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.

  • Published Sep 9, 2026
  • CVSS 4.6 medium
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-86776 at the National Vulnerability Database