Denial of Service Vulnerability in Plone App Portlets
CVE-2026-55248

9.1CRITICAL

Key Information:

Vendor

Plone

Vendor
CVE Published:
28 August 2026

What is CVE-2026-55248?

An issue exists in plone.app.portlets that allows users who can add RSS portlets to exploit the feed URL settings. When provided with a feed URL that generates a large response, this can lead to excessive data being stored in memory, resulting in a Denial of Service. Furthermore, this vulnerability permits server-side requests that can potentially access internal network services and open ports, enabling attackers to probe sensitive information. Additionally, malicious feed items may embed JavaScript URLs which could execute scripts when accessed by users, leading to further security risks. This vulnerability was addressed and patched in versions 5.0.8, 6.0.4, and 7.0.2.

Affected Version(s)

plone.app.portlets < 5.0.8 < 5.0.8

plone.app.portlets >= 6.0.0, < 6.0.4 < 6.0.0, 6.0.4

plone.app.portlets >= 7.0.0, < 7.0.2 < 7.0.0, 7.0.2

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.