Description

Velociraptor versions prior to 0.76.4 contain a resource exhaustion vulnerability in the server's agent control channel. This allows a compromised or rogue Velociraptor client to crash the server via out-of-memory (OOM) by sending crafted messages through the normal client communication channel.

INFO

Published Date :

2026-05-03T23:55:40.555Z

Last Modified :

2026-05-04T13:08:18.314Z

Source :

rapid7
AFFECTED PRODUCTS

The following products are affected by CVE-2026-6948 vulnerability.

Vendors Products
Rapid7
  • Velociraptor
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-6948.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact