Skip to content
Please update to the latest release 0.77.2 to address Multiple CVEs.

CVE-2026-77798: Velociraptor Authenticated Denial of Service

Published on 2026-09-21 Vulnogram
Description

Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock management bug in the user management module.

Problem CWE-833 Deadlock
ProductAffected
Rapid7 Velociraptor on Linux
source repo
Default status is unaffected
before 0.77.2
Credits
  • Yuval Miller and Leon Kayaliev