CVE-2026-72813
actix-files before 0.6.10 Denial of Service via empty Range header
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the process on-demand by sending a GET request with an empty Range header.
| CWE | CWE-248 |
| Vendor | actix |
| Product | actix-web |
| Published | Aug 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for actix actix-web
Be the first to know when new unknown vulnerabilities affecting actix actix-web are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
actix / actix-web
0 < 0.6.10
References
Credits
๐ Diomendius JohnTitor