CVE-2026-53596

MEDIUM

FreeScout has unrestricted file upload without rate limiting that leads to resource exhaustion (DoS)

Title source: cna
STIX 2.1

Description

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeScout helpdesk application does not enforce rate limiting on the file upload endpoint. Any user can flood the server with upload requests, leading to database overload and potential denial of service for all users. Version 1.8.224 contains a fix.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0024
EPSS Percentile 14.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-400 CWE-770
Status published
Products (1)
freescout-help-desk/freescout < 1.8.224
Published Jul 20, 2026
Tracked Since Jul 21, 2026