Denial of Service Vulnerability in Plone App Portlets
CVE-2026-55248
What is CVE-2026-55248?
An issue exists in plone.app.portlets that allows users who can add RSS portlets to exploit the feed URL settings. When provided with a feed URL that generates a large response, this can lead to excessive data being stored in memory, resulting in a Denial of Service. Furthermore, this vulnerability permits server-side requests that can potentially access internal network services and open ports, enabling attackers to probe sensitive information. Additionally, malicious feed items may embed JavaScript URLs which could execute scripts when accessed by users, leading to further security risks. This vulnerability was addressed and patched in versions 5.0.8, 6.0.4, and 7.0.2.
Affected Version(s)
plone.app.portlets < 5.0.8 < 5.0.8
plone.app.portlets >= 6.0.0, < 6.0.4 < 6.0.0, 6.0.4
plone.app.portlets >= 7.0.0, < 7.0.2 < 7.0.0, 7.0.2
