Velociraptor versions prior to 0.76.4 contain a resource exhaustion vulnerability in the server's agent control channel.



This allows a compromised or rogue Velociraptor client to crash the server via out-of-memory (OOM) by sending crafted messages through the normal client communication channel.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

To remediate, you will need to  upgrade your server https://www.velociraptor-docs.org/docs/deployment/server/upgrades/#upgrading-a-server-in-place-upgrade  to the latest version of your release: * For 0.76 releases, upgrade immediately to  v0.76.4 https://github.com/Velocidex/velociraptor/releases/download/v0.76/velociraptor-v0.76.4-linux-amd64 * For 0.75 releases, upgrade immediately to  v0.75.9 https://github.com/Velocidex/velociraptor/releases/download/v0.75/velociraptor-v0.75.9-linux-amd64


Workaround

No workaround given by the vendor.

History

Mon, 04 May 2026 00:15:00 +0000

Type Values Removed Values Added
Description Velociraptor versions prior to 0.76.4 contain a resource exhaustion vulnerability in the server's agent control channel. This allows a compromised or rogue Velociraptor client to crash the server via out-of-memory (OOM) by sending crafted messages through the normal client communication channel.
Title Unbounded Memory Allocation in VQLResponse Result-Set Writer
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published:

Updated: 2026-05-03T23:55:40.555Z

Reserved: 2026-04-24T03:35:48.568Z

Link: CVE-2026-6948

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-04T00:16:39.467

Modified: 2026-05-04T00:16:39.467

Link: CVE-2026-6948

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-04T01:30:33Z

Weaknesses