Denial of Service Vulnerability in Grav Web Platform
CVE-2026-62672
6MEDIUM
What is CVE-2026-62672?
Grav is a file-based web platform that previously allowed an authenticated page editor to exploit the regex_replace filter, leading to potential denial of service. When the process_enabled setting in security.twig_content was activated, an editor could publish a poorly structured regex pattern that caused excessive CPU consumption, effectively overwhelming PHP workers and disrupting access for site visitors. This vulnerability has been addressed in version 2.0.4, ensuring a more secure environment for users.
Affected Version(s)
grav < 2.0.4
