Description
Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files.
Published: 2026-09-24
Score: 3.6 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

This issue can result in a client crash. Usually clients will restart after a crash and resume normal operations. Users can collect the raw prefetch files without parsing them on the client for further analysis on the server.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Rapid7
Rapid7 velociraptor
Vendors & Products Rapid7
Rapid7 velociraptor

Thu, 24 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files.
Title Velociraptor Prefetch parser out of bounds
Weaknesses CWE-125
CWE-20
References
Metrics cvssV3_1

{'score': 3.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N'}


Subscriptions

Rapid7 Velociraptor
cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published:

Updated: 2026-09-24T14:47:56.068Z

Reserved: 2026-08-21T13:21:29.921Z

Link: CVE-2026-77797

cve-icon Vulnrichment

Updated: 2026-09-24T14:47:51.748Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-24T14:18:17.247

Modified: 2026-09-24T21:00:46.893

Link: CVE-2026-77797

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T01:45:16Z

Weaknesses