Denial of Service Vulnerability in Grav Web Platform
CVE-2026-62672

6MEDIUM

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-62672?

Grav is a file-based web platform that previously allowed an authenticated page editor to exploit the regex_replace filter, leading to potential denial of service. When the process_enabled setting in security.twig_content was activated, an editor could publish a poorly structured regex pattern that caused excessive CPU consumption, effectively overwhelming PHP workers and disrupting access for site visitors. This vulnerability has been addressed in version 2.0.4, ensuring a more secure environment for users.

Affected Version(s)

grav < 2.0.4

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.