File-Based Web Platform Vulnerability in Grav by GetGrav
CVE-2026-61690
6.5MEDIUM
What is CVE-2026-61690?
Grav, a file-based web platform, contains a vulnerability in the ZipArchiver functionality prior to version 2.0.1. This issue arises from the insufficient enforcement of limits on uncompressed size, file count, and nesting depth during the extraction of ZIP archives. An attacker could exploit this flaw by submitting a maliciously crafted archive, potentially leading to exhaustion of disk space or inodes. Consequently, this can render the site inaccessible, posing a serious risk to web availability. The vulnerability was resolved in version 2.0.1.
Affected Version(s)
grav < 2.0.1
