Security Advisory

CVE-2026-6948

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-03 23:55:40
Last updated 2026-06-19 12:45:13
Assigner rapid7
CVSS score 4.9
State PUBLISHED

Description

Velociraptor versions prior to 0.76.4 contain a resource exhaustion vulnerability in the server's agent control channel. This allows a compromised or rogue Velociraptor client to crash the server via out-of-memory (OOM) by sending crafted messages through the normal client communication channel.