PT-2026-78483 · Grav · Grav
CVE-2026-61690
·
Published
2026-08-19
·
Updated
2026-09-02
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Grav versions prior to 2.0.1
Description
The
ZipArchiver::extract() function in system/src/Grav/Common/Filesystem/ZipArchiver.php fails to enforce limits on uncompressed size, file count, or nesting depth when passing archives to ZipArchive::extractTo(). An attacker providing a specially crafted archive to code using Archiver::create('zip') can cause disk space or inode exhaustion, leading to a denial of service that makes the site unavailable.Recommendations
Update to version 2.0.1.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav