CVE-2026-61449

Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in 2.0.1 sums the uncompressed size declared in each entry's ZIP central-directory header (ZipArchive::statIndex()['size']) and rejects archives exceeding system.gpm.archive.max_uncompressed_size before extraction. Because this declared size is attacker-forgeable and is not cross-checked against the actual inflated stream, a crafted archive declaring tiny per-entry sizes passes the cap while extractTo() writes the real, much larger content, filling disk or exhausting inodes. The archive must be supplied by a package source or admin upload (admin/operator trust). Fixed in 2.0.2. This is an incomplete fix for GHSA-928x-9mpw-8h56.
Configurations

No configuration.

History

15 Jul 2026, 18:16

Type Values Removed Values Added
References () https://github.com/getgrav/grav/security/advisories/GHSA-8h9x-89f2-m7x3 - () https://github.com/getgrav/grav/security/advisories/GHSA-8h9x-89f2-m7x3 -

15 Jul 2026, 12:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-15 12:18

Updated : 2026-07-15 19:50


NVD link : CVE-2026-61449

Mitre link : CVE-2026-61449

CVE.ORG link : CVE-2026-61449


JSON object : View

Products Affected

No product.

CWE
CWE-409

Improper Handling of Highly Compressed Data (Data Amplification)