CVE-2018-20014: Urbackup

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin/CClientThread.cpp CClientThread::GetFileHashAndMetadata NULL pointer dereference, leading to shutting down the client application.

Affected products

Published 2019-06-07. Last modified 2026-06-17.