CVE-2026-17535

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
11/08/2026
Last modified:
11/08/2026

Description

Velociraptor&amp;#39;s NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images.<br /> <br /> Typically Velociraptor&amp;#39;s NTFS parser is used on live NTFS filesystems, limiting the opportunity of attackers corrupting the filesystem. However, in some applications (e.g.  dead disk forensics https://docs.velociraptor.app/docs/forensic/deaddisk/ ) Velociraptor may be used on untrusted NTFS image files. <br /> <br /> If an attacker is able to inject maliciously corrupted NTFS Volumes they can cause a crash and a Denial of Service.