Regular Expression Denial of Service Vulnerability in GROWI by GROWI, Inc.
CVE-2026-41040

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
23 April 2026

What is CVE-2026-41040?

The GROWI product developed by GROWI, Inc. is susceptible to a regular expression denial of service (ReDoS) attack when processed with specifically crafted input strings. This vulnerability could be exploited by attackers to induce excessive calculation cycles, leading to significant delays in application response times and potential denial of service for legitimate users, impacting the overall functionality and availability of GROWI services.

Affected Version(s)

GROWI v7.5.0 and earlier

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

CVSS V3.0

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.