File-Based Web Platform Vulnerability in Grav by GetGrav
CVE-2026-61690

6.5MEDIUM

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-61690?

Grav, a file-based web platform, contains a vulnerability in the ZipArchiver functionality prior to version 2.0.1. This issue arises from the insufficient enforcement of limits on uncompressed size, file count, and nesting depth during the extraction of ZIP archives. An attacker could exploit this flaw by submitting a maliciously crafted archive, potentially leading to exhaustion of disk space or inodes. Consequently, this can render the site inaccessible, posing a serious risk to web availability. The vulnerability was resolved in version 2.0.1.

Affected Version(s)

grav < 2.0.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.