Skip to content
Rapid7CVE-2026-17535

Rapid7 Velociraptor: denial of service

Medium6.2CVE-2026-17535 · Published Aug 11, 2026 · updated Aug 28, 2026

Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting the opportunity of attackers corrupting the filesystem. However, in some applications (e.g.  dead disk forensics https://docs.velociraptor.app/docs/forensic/deaddisk/ ) Velociraptor may be used on untrusted NTFS image files.  If an attacker is able to inject maliciously corrupted NTFS Volumes they can cause a crash and a Denial of Service.

Rapid7 advisory

Affected versions

PackageAffectedFixed in
Velociraptor
Product
< 0.77.20.77.2
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-125, CWE-369, CWE-789

More Rapid7 advisories

All Rapid7
Advisory
Rapid7 Velociraptor: null pointer dereference
Medium6.5Aug 11
Rapid7 Velociraptor: authentication bypass by spoofing
High7.3Aug 11
Rapid7 Velociraptor: path traversal
High7.1Aug 11
Rapid7 Velociraptor: improper authorization
High7.2Aug 11
Rapid7 Velociraptor: authentication bypass
Medium6.8Aug 11
Rapid7 Velociraptor: improper permission handling
High8.7Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.