CVE-2026-72813EPSS p40.1%
CVE-2026-72813CVE-2026-72813
Description
actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the process on-demand by sending a GET request with an empty Range header.
Scoring
| EPSS | 0.49% probability of exploitation · percentile 40.1% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-24 |