CVE-2026-53596
MEDIUMFreeScout has unrestricted file upload without rate limiting that leads to resource exhaustion (DoS)
Title source: cnaDescription
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeScout helpdesk application does not enforce rate limiting on the file upload endpoint. Any user can flood the server with upload requests, leading to database overload and potential denial of service for all users. Version 1.8.224 contains a fix.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-ph4f-2jhx-q76w
Scores
CVSS v3
5.3
EPSS
0.0024
EPSS Percentile
14.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-400
CWE-770
Status
published
Products (1)
freescout-help-desk/freescout
< 1.8.224
Published
Jul 20, 2026
Tracked Since
Jul 21, 2026