CVE-2026-6948
MEDIUMUnbounded Memory Allocation in VQLResponse Result-Set Writer
Title source: cnaDescription
Velociraptor versions prior to 0.76.4 contain a resource exhaustion vulnerability in the server's agent control channel. This allows a compromised or rogue Velociraptor client to crash the server via out-of-memory (OOM) by sending crafted messages through the normal client communication channel.
References (1)
Core 1
Scores
CVSS v3
4.9
EPSS
0.0034
EPSS Percentile
26.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-770
Status
published
Products (2)
Rapid7/Velociraptor
< 0.75.9
Rapid7/Velociraptor
< 0.76.4
Published
May 04, 2026
Tracked Since
May 04, 2026