Cloudreve Storage Quota Bypass via TOCTOU Race Condition
Cloudreve v4 contains a Time-of-Check to Time-of-Use (TOCTOU) vulnerability that allows authenticated users to bypass storage quotas and exhaust host disk space by triggering concurrent, non-atomic upload session reservations.
CVE search metadata
CVE search record: CVE-2026-77633. Severity: high. CVSS: 7.1. KEV: no. Product: Cloudreve (v4 < 4.0.0-20260715025621-7329602751c0). Brief: Cloudreve Storage Quota Bypass via TOCTOU Race Condition. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cloudreve-quota-bypass/
Cloudreve v4 is vulnerable to a TOCTOU race condition within its PrepareUpload function, which governs how user storage quotas are enforced. The application fails to perform atomic quota checks and balance updates, separating the process into two distinct stages: a check (reading the current used byte count from the database) and a charge (incrementing the users.storage field).
Because these operations are not enclosed within a database-level transaction lock (e.g., SELECT ... FOR UPDATE), multiple concurrent upload requests can read the same stale storage snapshot. This enables attackers to bypass MaxStorage limits defined by their user group. By sending multiple simultaneous requests, an attacker can reserve storage far exceeding their actual quota. This primitive is trivially escalated to a storage-based denial of service, where the reserved storage eventually materializes as actual file data written to disk, potentially exhausting the host's physical free space and disrupting service for all users. This vulnerability impacts all default deployments of Cloudreve v4 prior to version 4.0.0-20260715025621-7329602751c0.
Attack Chain
- Attacker authenticates to the Cloudreve instance using a standard user account with
Files.Writepermissions. - Attacker initiates multiple concurrent upload sessions (e.g., via script) targeting the
PrepareUploadendpoint. - The
DBFS.validateUserCapacityfunction for each request fetches theusedstorage value from the database snapshot simultaneously. - Each request process performs a validation check against the user's
MaxStoragelimit using the same stale usage value, all passing simultaneously. - Each request proceeds to the
inventory.CommitWithStorageDiffstage, where the total requested size is added to the user'sstoragecolumn in the database. - The sum of all concurrent reservations exceeds the configured
MaxStoragequota. - Attacker completes the chunked uploads for all sessions, writing excess data to the physical disk.
- Host disk space is exhausted, causing a denial of service for all users on the instance.
Impact
Successful exploitation allows any authenticated user to ignore storage limitations, leading to unauthorized resource consumption and potential denial of service. By filling the host server's storage partition, an attacker can prevent all users from uploading files or accessing services, causing total availability loss for the Cloudreve instance.
Recommendation
Prioritized actions for administrators:
- Upgrade Cloudreve to version 4.0.0-20260715025621-7329602751c0 or later to patch CVE-2026-77633.
- Monitor logs for unusual spikes in rapid, concurrent
PrepareUploadrequests originating from a single user session. - Implement external storage monitoring to alert on rapid decreases in host filesystem availability, which may indicate storage-based DoS exploitation.
Immediate actions
Upgrade Cloudreve to version 4.0.0-20260715025621-7329602751c0 or later
Mitigations
Upgrade to version 4.0.0-20260715025621-7329602751c0
CVE-2026-77633