Denial of Service Vulnerability in Elgg Provides Unrestricted Avatar Uploads
CVE-2026-65650
4.3MEDIUM
What is CVE-2026-65650?
Elgg versions before 7.0.0 allow an attacker to exploit the image upload feature by submitting oversized avatar images, leading to potential Denial of Service conditions. The application fails to adequately validate image dimensions, which can overwhelm system resources. This vulnerability underscores the importance of implementing stricter input validation controls to maintain system performance and availability.
Affected Version(s)
Elgg 0 < 6.3.5
Elgg 7.0.0-rc.1 < 7.0.0
