Junglewise Threat Intelligence

CVE-2026-41040: GROWI ReDoS denial of service via crafted input string

CVE-2026-41040 · Severity: high · CVSS 7.5 · Published 2026-04-23

Technologies: GROWI, Inc. GROWI.

Executive brief

GROWI, a collaborative wiki and knowledge management platform, is vulnerable to a security flaw that can be used to crash the service. By sending a specially crafted text string, an attacker can overwhelm the system's processing power, making the platform unavailable to legitimate users. This could disrupt business operations and internal documentation access until the service is restored.

Technical details

GROWI v7.5.0 and earlier contains an inefficient regular expression complexity vulnerability (CWE-1333). An unauthenticated remote attacker can exploit this by providing a specially crafted input string that triggers catastrophic backtracking during regex evaluation. This results in excessive CPU consumption, leading to a Denial of Service (DoS) condition for the application. The vulnerability is addressed in GROWI v7.5.1 and later versions.

Affected products

  • GROWI, Inc. GROWI v7.5.0 and earlier

Timeline

  • 2026-04-23: disclosed
  • 2026-04-23: advisory
  • 2026-04-28: patched: Vendor update status confirmed; version 7.5.1 released.

References