PT-2026-57198 · Grav · Grav
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Grav versions prior to 2.0.1
Description
A decompression bomb issue exists in the
ZipArchiver::extract() function. The function does not impose limits on the number of files, nesting depth, or the total uncompressed size of archives. An attacker can provide a specially crafted ZIP archive that expands to consume all available disk space, resulting in a denial of service by exhausting storage resources.Recommendations
Update Grav to version 2.0.1 or later.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav