CVE-2026-72813: actix-files before 0.6.10 Denial of Service via empty Range header
Published Aug 14, 2026
·Updated
actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the process on-demand by sending a GET request with an empty Range header.
Affected Software
1 affected component
actix-files<0.6.10
Event History
Aug 14, 2026
CVE Published
via MITRE·11:35 AM
Data Sourced
via MITRE·11:35 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-72813?
CVE-2026-72813 has a risk score of 45, indicating a moderate severity denial of service vulnerability.
2
How do I fix CVE-2026-72813?
To fix CVE-2026-72813, upgrade actix-files to version 0.6.10 or later.
3
What causes the vulnerability CVE-2026-72813?
CVE-2026-72813 is caused by the handling of an empty Range header in GET requests for static files.
4
What impact does CVE-2026-72813 have on my application?
CVE-2026-72813 allows remote attackers to crash the application process through specially crafted GET requests.
5
Is CVE-2026-72813 present in all versions of actix-files?
CVE-2026-72813 affects all versions of actix-files prior to 0.6.10.