
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-6948 is a resource exhaustion vulnerability in Velociraptor's server agent control channel, classified as Moderate severity. It affects Velociraptor versions prior to 0.76.4 (and prior to 0.75.9 in the 0.75.x branch), allowing a compromised or rogue client to crash the server via an out-of-memory (OOM) condition by sending crafted messages through the normal client communication channel. The vulnerability was published on May 4, 2026, with a patch available in version 0.76.4. It carries a CVSS v3.1 base score of 4.9 (Medium) (GitHub Advisory, Feedly).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), specifically in the VQLResponse result set writer component of the Velociraptor server. The server fails to impose limits on memory allocation when processing messages received from connected clients over the agent control channel, enabling unbounded memory consumption. Exploitation requires network access and high privileges (i.e., the attacker must control a Velociraptor client — either a compromised legitimate client or a rogue one enrolled in the server). A technical write-up describing the unbounded memory allocation in the VQLResponse result set writer is available at infinitsec.net (GitHub Advisory, Velociraptor Advisory).
Successful exploitation results in a denial-of-service condition, crashing the Velociraptor server process via OOM, which renders all agent management, endpoint monitoring, and forensic investigation capabilities unavailable. There is no confidentiality or integrity impact — the vulnerability is limited to availability. Because Velociraptor is commonly used as a DFIR and endpoint detection platform, its unavailability could disrupt active incident response operations across all managed endpoints (GitHub Advisory, Feedly).
top, htop, Task Manager); unexpected server process termination or restart events.Upgrade Velociraptor to version 0.76.4 or later (or 0.75.9 for the 0.75.x branch), which includes fixes for the unbounded memory allocation in the agent control channel. As an interim measure, implement network-level access controls (firewall rules, allowlists) to restrict which systems can connect as Velociraptor clients to the server, reducing exposure to rogue or compromised clients. Monitor server memory usage for anomalous growth patterns that may indicate exploitation attempts (Velociraptor Advisory, GitHub Advisory).
The vulnerability was assigned by Rapid7 (the maintainer of Velociraptor) and disclosed via the official Velociraptor documentation site alongside the GitHub Advisory Database. Community reaction has been limited given the moderate severity and the high-privilege precondition required for exploitation. No notable independent researcher commentary or significant media coverage has been identified beyond standard vulnerability aggregator listings (Velociraptor Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."