CVE-2026-6948
Velociraptor vulnerability analysis and mitigation

Overview

CVE-2026-6948 is a resource exhaustion vulnerability in Velociraptor's server agent control channel, classified as Moderate severity. It affects Velociraptor versions prior to 0.76.4 (and prior to 0.75.9 in the 0.75.x branch), allowing a compromised or rogue client to crash the server via an out-of-memory (OOM) condition by sending crafted messages through the normal client communication channel. The vulnerability was published on May 4, 2026, with a patch available in version 0.76.4. It carries a CVSS v3.1 base score of 4.9 (Medium) (GitHub Advisory, Feedly).

Technical details

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), specifically in the VQLResponse result set writer component of the Velociraptor server. The server fails to impose limits on memory allocation when processing messages received from connected clients over the agent control channel, enabling unbounded memory consumption. Exploitation requires network access and high privileges (i.e., the attacker must control a Velociraptor client — either a compromised legitimate client or a rogue one enrolled in the server). A technical write-up describing the unbounded memory allocation in the VQLResponse result set writer is available at infinitsec.net (GitHub Advisory, Velociraptor Advisory).

Impact

Successful exploitation results in a denial-of-service condition, crashing the Velociraptor server process via OOM, which renders all agent management, endpoint monitoring, and forensic investigation capabilities unavailable. There is no confidentiality or integrity impact — the vulnerability is limited to availability. Because Velociraptor is commonly used as a DFIR and endpoint detection platform, its unavailability could disrupt active incident response operations across all managed endpoints (GitHub Advisory, Feedly).

Exploitation steps

  1. Obtain client access: Compromise an existing Velociraptor client endpoint, or deploy a rogue system that has been enrolled as a legitimate Velociraptor client against the target server.
  2. Establish communication channel: Use the compromised or rogue client to connect to the Velociraptor server over the normal agent control channel (typically HTTPS).
  3. Craft malicious messages: Construct oversized or specially crafted VQLResponse messages designed to trigger unbounded memory allocation in the server's result set writer, without any server-side size restrictions.
  4. Send crafted messages: Transmit the crafted messages repeatedly through the client communication channel to progressively exhaust server memory.
  5. Trigger OOM crash: The server process exhausts available memory and crashes, resulting in a denial-of-service condition that disrupts all connected agents and forensic operations (Velociraptor Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Unusual volume of large or malformed messages from a single Velociraptor client to the server's agent control port; unexpected spikes in inbound traffic from enrolled client IPs.
  • Logs: Velociraptor server logs showing repeated or oversized VQLResponse submissions from a specific client ID; OOM-related error messages or panic traces in server logs prior to crash.
  • Process/System: Rapid increase in Velociraptor server process memory consumption visible in system monitoring tools (e.g., top, htop, Task Manager); unexpected server process termination or restart events.
  • Behavioral: Velociraptor server becoming unresponsive or restarting repeatedly; all connected agents losing connectivity to the server simultaneously (Velociraptor Advisory).

Mitigation and workarounds

Upgrade Velociraptor to version 0.76.4 or later (or 0.75.9 for the 0.75.x branch), which includes fixes for the unbounded memory allocation in the agent control channel. As an interim measure, implement network-level access controls (firewall rules, allowlists) to restrict which systems can connect as Velociraptor clients to the server, reducing exposure to rogue or compromised clients. Monitor server memory usage for anomalous growth patterns that may indicate exploitation attempts (Velociraptor Advisory, GitHub Advisory).

Community reactions

The vulnerability was assigned by Rapid7 (the maintainer of Velociraptor) and disclosed via the official Velociraptor documentation site alongside the GitHub Advisory Database. Community reaction has been limited given the moderate severity and the high-privilege precondition required for exploitation. No notable independent researcher commentary or significant media coverage has been identified beyond standard vulnerability aggregator listings (Velociraptor Advisory, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Velociraptor vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-6290CRITICAL9.1
  • Velociraptor logoVelociraptor
  • www.velocidex.com/golang/velociraptor
NoYesApr 15, 2026
CVE-2026-8795HIGH7.8
  • Velociraptor logoVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesJun 09, 2026
CVE-2026-7573HIGH7.7
  • Velociraptor logoVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesMay 06, 2026
CVE-2026-7572MEDIUM5.5
  • Velociraptor logoVelociraptor
  • www.velocidex.com/golang/velociraptor
NoYesMay 06, 2026
CVE-2026-6948MEDIUM4.9
  • Velociraptor logoVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesMay 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management