CVE-2026-57581: CWE-434: Unrestricted Upload of File with Dangerous Type in riganti dotvvm
DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applications with configured file upload storage allow unauthenticated users to submit files directly to DotvvmFileUploadMiddleware without an X-DotVVM-UploadToken generated by the FileUpload component. An attacker can repeatedly upload files and fill application storage, causing denial of service. DotvvmConfiguration.Security.AuthorizeFileUpload can additionally restrict which users may upload files. This issue is fixed in versions 4.2.11, 4.3.15, and 5.0.0-preview09-final.
AI Analysis
Technical Summary
DotVVM, an open source MVVM framework, has an unrestricted file upload vulnerability (CWE-434) in versions before 4.2.11, 4.3.15, and 5.0.0-preview09-final. Applications with configured file upload storage allow unauthenticated users to submit files directly to DotvvmFileUploadMiddleware without the X-DotVVM-UploadToken generated by the FileUpload component. This enables attackers to repeatedly upload files and exhaust storage resources, causing denial of service. The vulnerability can be further restricted by DotvvmConfiguration.Security.AuthorizeFileUpload, which limits upload permissions to authorized users. The issue is addressed in the fixed versions 4.2.11, 4.3.15, and 5.0.0-preview09-final.
Potential Impact
An attacker can cause denial of service by filling the application storage through repeated unauthorized file uploads. There is no confidentiality or integrity impact reported. The vulnerability requires no privileges or user interaction.
Mitigation Recommendations
Upgrade to DotVVM versions 4.2.11, 4.3.15, or 5.0.0-preview09-final or later where the vulnerability is fixed. Additionally, configure DotvvmConfiguration.Security.AuthorizeFileUpload to restrict file upload permissions to authorized users. No other mitigation is indicated by the vendor advisory.
CVE-2026-57581: CWE-434: Unrestricted Upload of File with Dangerous Type in riganti dotvvm
Description
DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applications with configured file upload storage allow unauthenticated users to submit files directly to DotvvmFileUploadMiddleware without an X-DotVVM-UploadToken generated by the FileUpload component. An attacker can repeatedly upload files and fill application storage, causing denial of service. DotvvmConfiguration.Security.AuthorizeFileUpload can additionally restrict which users may upload files. This issue is fixed in versions 4.2.11, 4.3.15, and 5.0.0-preview09-final.
CVSS v3.1
Score 5.3medium
Affected software
riganti
dotvvm
pkg:github/riganti/dotvvmRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
DotVVM, an open source MVVM framework, has an unrestricted file upload vulnerability (CWE-434) in versions before 4.2.11, 4.3.15, and 5.0.0-preview09-final. Applications with configured file upload storage allow unauthenticated users to submit files directly to DotvvmFileUploadMiddleware without the X-DotVVM-UploadToken generated by the FileUpload component. This enables attackers to repeatedly upload files and exhaust storage resources, causing denial of service. The vulnerability can be further restricted by DotvvmConfiguration.Security.AuthorizeFileUpload, which limits upload permissions to authorized users. The issue is addressed in the fixed versions 4.2.11, 4.3.15, and 5.0.0-preview09-final.
Potential Impact
An attacker can cause denial of service by filling the application storage through repeated unauthorized file uploads. There is no confidentiality or integrity impact reported. The vulnerability requires no privileges or user interaction.
Mitigation Recommendations
Upgrade to DotVVM versions 4.2.11, 4.3.15, or 5.0.0-preview09-final or later where the vulnerability is fixed. Additionally, configure DotvvmConfiguration.Security.AuthorizeFileUpload to restrict file upload permissions to authorized users. No other mitigation is indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-24T18:49:56.209Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa8337755bf5e2cf5641816
Added to database: 09/14/2026, 17:48:39 UTC
Last enriched: 09/14/2026, 18:02:04 UTC
Last updated: 09/15/2026, 03:14:35 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.