CVE-2026-77633: Storage-quota Time-of-Check to Time-of-Use (TOCTOU) Race Condition in Cloudreve
Vulnerability ID: CVE-2026-77633
CVSS Score: 7.1
Published: 2026-09-22
Cloudreve before version 4.18.0 contains a Time-of-Check to Time-of-Use (TOCTOU) race condition in its storage-quota verification logic. Authenticated attackers with basic write access can trigger multiple parallel upload sessions to bypass their storage limits, leading to host disk space exhaustion and Denial of Service.
TL;DR
A TOCTOU race condition in Cloudreve allows authenticated users to bypass their storage quota limits via concurrent upload sessions, causing host disk exhaustion.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-367 / CWE-770
- Attack Vector: Network (AV:N)
- CVSS v3.1: 7.1 (High)
- Exploit Status: PoC / Conceptual
- KEV Status: Not Listed
- Impact: Denial of Service (DoS) via Disk Exhaustion
Affected Systems
- Cloudreve
-
Cloudreve: < 4.18.0 (Fixed in:
4.18.0)
Code Analysis
Commit: 7329602
fix(dbfs): enforce storage pre allocate before creating file placeholders
Mitigation Strategies
- Upgrade to Cloudreve version 4.18.0 or later.
- Implement rate limiting at the reverse proxy level on upload endpoints.
- Configure cloud storage policies (S3, B2, etc.) to isolate storage consumption.
Remediation Steps:
- Stop the Cloudreve service.
- Download the Cloudreve v4.18.0 binary or build from source.
- Update your service configuration and restart the application.
- Configure rate limits in Nginx/Apache for POST requests targeting '/api/v3/file/upload'.
References
Read the full report for CVE-2026-77633 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)