Vulnerability Intelligence Report
HFS2 2.4.0 Unauthenticated Denial of Service via Hung Serving Thread
CVE-2026-97362
HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request. Attackers can trigger a hung serving thread that enters a busy loop, rendering the entire file server unresponsive to all clients without self-recovery until an operator manually restarts the service.
No Active Exploit Signals
CVSS Base Score
8.7
HIGH
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-835 ↗Loop with Unreachable Exit Condition ('Infinite Loop')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| rejetto | hfs2 | 2.0.0 <= 2.4.0 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VulnCheck · Bug Bounty Provider · USA |
| Reserved | 2026-09-24T13:33:30 |
| Published | 2026-09-24T14:49:15 |
| Patch Date | 2026-09-24 |
| Last Updated | 2026-09-24T15:47:35 |
Community Chatter & Buzz