CVE-2026-23835Disclosure

LOWCVSS 5.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

LobeHub is an open source human-and-AI-agent network. Prior to version 1.143.3, the file upload feature in `Knowledge Base > File Upload` does not validate the integrity of the upload request, allowing users to intercept and modify the request parameters. As a result, it is possible to create arbitrary files in abnormal or unintended paths. In addition, since `lobechat.com` relies on the size parameter from the request to calculate file usage, an attacker can manipulate this value to misrepresent the actual file size, such as uploading a `1 GB` file while reporting it as `10 MB`, or falsely declaring a `10 MB` file as a `1 GB` file. By manipulating the size value provided in the client upload request, it is possible to bypass the monthly upload quota enforced by the server and continuously upload files beyond the intended storage and traffic limits. This abuse can result in a discrepancy between actual resource consumption and billing calculations, causing direct financial impact to the service operator. Additionally, exhaustion of storage or related resources may lead to degraded service availability, including failed uploads, delayed content delivery, or temporary suspension of upload functionality for legitimate users. A single malicious user can also negatively affect other users or projects sharing the same subscription plan, effectively causing an indirect denial of service (DoS). Furthermore, excessive and unaccounted-for uploads can distort monitoring metrics and overload downstream systems such as backup processes, malware scanning, and media processing pipelines, ultimately undermining overall operational stability and service reliability. Version 1.143.3 contains a patch for the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-01-30); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-01-30: 2Mentions · 2026-02-01: 1Mentions · 2026-02-07: 1Technical Details · 2026-01-30: 1Technical Details · 2026-02-01: 1Technical Details · 2026-02-07: 101-3002-0102-07
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-302
Disclosure1General1
2026-02-011
Disclosure1
2026-02-071
Disclosure1
Full discourse4 posts
  • Henry Raúl Glez Brito@henryraul
    Disclosure

    4/ DoS por evaluación excesiva: Expresiones profundas en ORM y plantillas podían generar consumo anómalo de CPU/memoria. Riesgo: caída del servicio. CVE-2026-23835 @OWASP_Sevilla @python_es @universidad_uci @UIC_Cuba #Django #CyberSecurity #InfoSec

    Post summary

    CVE-2026-23835 is a denial‑of‑service vulnerability in Django where overly complex ORM or template expressions can overconsume CPU/memory, causing service crashes.

    1001182
    11.3K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 LobeChat, File Upload Parameter Manipulation, #CVE-2026-23835 (Critical) https://dailycve.com/lobechat-file-upload-parameter-manipulation-cve-2026-23835-critical/

    Post summary

    A new critical CVE (CVE-2026-23835) affecting LobeChat’s file upload parameter handling has been announced; the linked article offers additional details.

    00000101
    162 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-23835 LobeHub is an open source human-and-AI-agent network. Prior to version 1.143.3, the file upload feature in `Knowledge Base > File Upload` does not validate the integr… https://www.cve.org/CVERecord?id=CVE-2026-23835

    Post summary

    CVE-2026-23835 impacts LobeHub’s file upload feature before version 1.143.3, lacking validation. No PoC, exploit, patch, or active exploitation is reported.

    00000235
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23835 LobeHub File Upload Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23835

    Post summary

    The text announces CVE‑2026‑23835, a file upload vulnerability in LobeHub, but offers no further technical or remediation details.

    0000085
    4.0K followersView on X

Explore more