CVE-2026-61449

MEDIUM

Grav before 2.0.2 Decompression Bomb via Forged ZIP Size

Title source: cna
STIX 2.1

Description

Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in 2.0.1 sums the uncompressed size declared in each entry's ZIP central-directory header (ZipArchive::statIndex()['size']) and rejects archives exceeding system.gpm.archive.max_uncompressed_size before extraction. Because this declared size is attacker-forgeable and is not cross-checked against the actual inflated stream, a crafted archive declaring tiny per-entry sizes passes the cap while extractTo() writes the real, much larger content, filling disk or exhausting inodes. The archive must be supplied by a package source or admin upload (admin/operator trust). Fixed in 2.0.2. This is an incomplete fix for GHSA-928x-9mpw-8h56.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-8h9x-89f2-m7x3)
https://github.com/getgrav/grav/security/advisories/GHSA-8h9x-89f2-m7x3
Third Party Advisory third-party-advisory
VulnCheck Advisory: Grav before 2.0.2 Decompression Bomb via Forged ZIP Size
https://www.vulncheck.com/advisories/grav-before-decompression-bomb-via-forged-zip-size

Scores

CVSS v3 6.5
EPSS 0.0025
EPSS Percentile 16.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-409
Status published
Products (2)
getgrav/grav < 2.0.2
getgrav/grav 2.0.2
Published Jul 15, 2026
Tracked Since Jul 15, 2026