CVE-2026-61455

Grav before 2.0.1 contains a decompression bomb vulnerability in ZipArchiver::extract() that lacks limits on uncompressed size, file count, and nesting depth. Attackers can supply a crafted ZIP archive that expands to fill available disk space, causing denial of service by exhausting storage resources.
Configurations

No configuration.

History

10 Jul 2026, 16:16

Type Values Removed Values Added
References () https://github.com/getgrav/grav/security/advisories/GHSA-928x-9mpw-8h56 - () https://github.com/getgrav/grav/security/advisories/GHSA-928x-9mpw-8h56 -

10 Jul 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-10 15:16

Updated : 2026-07-10 17:41


NVD link : CVE-2026-61455

Mitre link : CVE-2026-61455

CVE.ORG link : CVE-2026-61455


JSON object : View

Products Affected

No product.

CWE
CWE-409

Improper Handling of Highly Compressed Data (Data Amplification)