Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-61449— Grav before 2.0.2 Decompression Bomb via Forged ZIP Size

Quick assessment

Affected
getgrav grav
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

getgrav Grav是getgrav个人开发者开源的一套可扩展的内容管理系统。 getgrav Grav 2.0.1版本存在资源管理错误漏洞,该漏洞源于ZipArchiver和GPM\Installer中存在解压炸弹大小上限绕过漏洞,攻击者在声明每个条目ZIP中央目录标头中未压缩大小时可伪造,导致特制归档文件绕过大小上限并写出实际更大内容,从而填满磁盘或耗尽inode。

CVSS 6.5 · Medium EPSS 0.44% · P36

Affected Version Matrix 2

VendorProduct Version RangeStatus
getgrav grav < 2.0.2 affected
2.0.2 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-61449

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Grav before 2.0.2 Decompression Bomb via Forged ZIP Size
Source: CVE Program / CVE List V5
Vulnerability Description
Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in 2.0.1 sums the uncompressed size declared in each entry's ZIP central-directory header (ZipArchive::statIndex()['size']) and rejects archives exceeding system.gpm.archive.max_uncompressed_size before extraction. Because this declared size is attacker-forgeable and is not cross-checked against the actual inflated stream, a crafted archive declaring tiny per-entry sizes passes the cap while extractTo() writes the real, much larger content, filling disk or exhausting inodes. The archive must be supplied by a package source or admin upload (admin/operator trust). Fixed in 2.0.2. This is an incomplete fix for GHSA-928x-9mpw-8h56.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对高度压缩数据的处理不恰当(数据放大攻击)
Source: CVE Program / CVE List V5
Vulnerability Title
getgrav Grav 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
getgrav Grav是getgrav个人开发者开源的一套可扩展的内容管理系统。 getgrav Grav 2.0.1版本存在资源管理错误漏洞,该漏洞源于ZipArchiver和GPM\Installer中存在解压炸弹大小上限绕过漏洞,攻击者在声明每个条目ZIP中央目录标头中未压缩大小时可伪造,导致特制归档文件绕过大小上限并写出实际更大内容,从而填满磁盘或耗尽inode。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
getgrav grav 0 ~ 2.0.2 -

II. Public POCs for CVE-2026-61449

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-61449

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-61449 (2)

Same Patch Batch · getgrav · 2026-07-15 · 7 CVEs total

CVE-2026-61451 9.6 CRITICAL Grav before 1.0.4 Password Reset Token Poisoning via admin_base_url
CVE-2026-58655 8.8 HIGH Grav Flex Objects - Server-Side Template Injection via Dynamic Titles
CVE-2026-61457 8.8 HIGH Grav before 1.0.3 Remote Code Execution via File Upload Extension Bypass
CVE-2026-61873 8.1 HIGH Grav before 9.1.8 Arbitrary File Write via Twig-Processed Filename
CVE-2026-61453 6.1 MEDIUM Grav before 2.0.1 XSS via Twig String Concatenation
CVE-2026-61452 5.3 MEDIUM Grav before 2.0.4 Improper Session Invalidation JWT Access Tokens

IV. Related Vulnerabilities

V. Comments for CVE-2026-61449

No comments yet


Leave a comment