Executive brief
GROWI, a collaborative wiki and knowledge management platform, is vulnerable to a security flaw that can be used to crash the service. By sending a specially crafted text string, an attacker can overwhelm the system's processing power, making the platform unavailable to legitimate users. This could disrupt business operations and internal documentation access until the service is restored.
Technical details
GROWI v7.5.0 and earlier contains an inefficient regular expression complexity vulnerability (CWE-1333). An unauthenticated remote attacker can exploit this by providing a specially crafted input string that triggers catastrophic backtracking during regex evaluation. This results in excessive CPU consumption, leading to a Denial of Service (DoS) condition for the application. The vulnerability is addressed in GROWI v7.5.1 and later versions.
Affected products
- GROWI, Inc. GROWI v7.5.0 and earlier
Timeline
- 2026-04-23: disclosed
- 2026-04-23: advisory
- 2026-04-28: patched: Vendor update status confirmed; version 7.5.1 released.