CVE-2026-6948
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/05/2026
Last modified:
04/05/2026
Description
Velociraptor versions prior to 0.76.4 contain a resource exhaustion vulnerability in the server&#39;s agent control channel.<br />
<br />
<br />
<br />
This allows a compromised or rogue Velociraptor client to crash the server via out-of-memory (OOM) by sending crafted messages through the normal client communication channel.
Impact
Base Score 3.x
4.90
Severity 3.x
MEDIUM



