CVE-2026-86776: Keepass

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.

Affected products

  • Keepass Keepass: from 2.35, up to and including 2.61.1

Published 2026-09-09. Last modified 2026-09-10.