Regular Expression Denial of Service Vulnerability in GROWI by GROWI, Inc.
CVE-2026-41040
8.7HIGH
What is CVE-2026-41040?
The GROWI product developed by GROWI, Inc. is susceptible to a regular expression denial of service (ReDoS) attack when processed with specifically crafted input strings. This vulnerability could be exploited by attackers to induce excessive calculation cycles, leading to significant delays in application response times and potential denial of service for legitimate users, impacting the overall functionality and availability of GROWI services.
Affected Version(s)
GROWI v7.5.0 and earlier
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
CVSS V3.0
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
