DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-77633: CVE-2026-77633: Storage-quota Time-of-Check to Time-of-Use (TOCTOU) Race Condition in Cloudreve

CVE-2026-77633: Storage-quota Time-of-Check to Time-of-Use (TOCTOU) Race Condition in Cloudreve

Vulnerability ID: CVE-2026-77633
CVSS Score: 7.1
Published: 2026-09-22

Cloudreve before version 4.18.0 contains a Time-of-Check to Time-of-Use (TOCTOU) race condition in its storage-quota verification logic. Authenticated attackers with basic write access can trigger multiple parallel upload sessions to bypass their storage limits, leading to host disk space exhaustion and Denial of Service.

TL;DR

A TOCTOU race condition in Cloudreve allows authenticated users to bypass their storage quota limits via concurrent upload sessions, causing host disk exhaustion.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-367 / CWE-770
  • Attack Vector: Network (AV:N)
  • CVSS v3.1: 7.1 (High)
  • Exploit Status: PoC / Conceptual
  • KEV Status: Not Listed
  • Impact: Denial of Service (DoS) via Disk Exhaustion

Affected Systems

  • Cloudreve
  • Cloudreve: < 4.18.0 (Fixed in: 4.18.0)

Code Analysis

Commit: 7329602

fix(dbfs): enforce storage pre allocate before creating file placeholders

Mitigation Strategies

  • Upgrade to Cloudreve version 4.18.0 or later.
  • Implement rate limiting at the reverse proxy level on upload endpoints.
  • Configure cloud storage policies (S3, B2, etc.) to isolate storage consumption.

Remediation Steps:

  1. Stop the Cloudreve service.
  2. Download the Cloudreve v4.18.0 binary or build from source.
  3. Update your service configuration and restart the application.
  4. Configure rate limits in Nginx/Apache for POST requests targeting '/api/v3/file/upload'.

References


Read the full report for CVE-2026-77633 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)