PT-2026-57198 · Grav · Grav

·

CVE-2026-61455

·

Published

2026-07-10

·

Updated

2026-09-02

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grav versions prior to 2.0.1
Description A decompression bomb issue exists in the ZipArchiver::extract() function. The function does not impose limits on the number of files, nesting depth, or the total uncompressed size of archives. An attacker can provide a specially crafted ZIP archive that expands to consume all available disk space, resulting in a denial of service by exhausting storage resources.
Recommendations Update Grav to version 2.0.1 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61455
GHSA-928X-9MPW-8H56

Affected Products

Grav