CVE-2026-72813: Actix Actix-Web
Medium severity, CVSS 6.9. EPSS: 0.5% chance of exploitation in the next 30 days.
actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the process on-demand by sending a GET request with an empty Range header.
Affected products
- Actix Actix-Web: before 0.6.10 (fixed in 0.6.10)
Published 2026-08-14. Last modified 2026-09-24.