CVE-2026-6948: Unbounded Memory Allocation in VQLResponse Result-Set Writer
Velociraptor versions prior to 0.76.4 contain a resource exhaustion vulnerability in the server's agent control channel.
This allows a compromised or rogue Velociraptor client to crash the server via out-of-memory (OOM) by sending crafted messages through the normal client communication channel.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
velociraptor/serverto a version that resolves this vulnerability.Fixed in 0.75.9 - Upgrade
Upgrade
velociraptor/serverto a version that resolves this vulnerability.Fixed in 0.76.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6948?
CVE-2026-6948 has a severity level that can lead to resource exhaustion and potential server crashes.
How do I fix CVE-2026-6948?
To fix CVE-2026-6948, upgrade Velociraptor to version 0.76.4 or later.
Who is affected by CVE-2026-6948?
CVE-2026-6948 affects users of Velociraptor versions prior to 0.76.4.
What causes CVE-2026-6948?
CVE-2026-6948 is caused by unbounded memory allocation in the server's agent control channel.
What type of vulnerability is CVE-2026-6948?
CVE-2026-6948 is a resource exhaustion vulnerability that can lead to out-of-memory (OOM) conditions.