Junglewise Threat Intelligence

CVE-2026-61449: Grav decompression bomb size-cap bypass in ZipArchiver

CVE-2026-61449 · Severity: medium · CVSS 6.5 · Published 2026-07-15

Technologies: Getgrav Grav, Grav, getgrav/grav (Packagist). Vendors: Getgrav, Grav, Packagist.

Executive brief

Grav is a flat-file CMS used to build websites without a database. When administrators install packages, restore backups, or upgrade the system, Grav extracts ZIP archives. A malicious or compromised ZIP can declare tiny file sizes while actually containing massive amounts of data, bypassing Grav's safeguard against decompression bombs. This causes the server's disk to fill up completely, shutting down the website and wasting storage resources. While currently limited to admin-level actors with upload/install privileges, the vulnerability completely defeats a critical resource-exhaustion protection.

Technical details

The vulnerability is a decompression-bomb bypass in ZIP extraction logic (`ZipArchiver.php:77–86` and `Installer.php:228–238`). Both code paths validate archive size by summing `ZipArchive::statIndex($i)['size']`, which reads uncompressed sizes declared in the ZIP central directory. This value is attacker-forgeable; libzip's `extractTo()` does not cross-check declared vs. actual inflated stream size during extraction. An attacker crafts a 10 KiB deflate-compressed ZIP containing 10 MiB of zeros, then patches both the local and central directory size fields to `1`, causing the pre-extraction validation to report total size of 1 byte (passing the cap) while `extractTo()` writes the actual 10 MiB to disk. Reachable via `GPM\Installer::unZip` (package install, direct-install, self-upgrade) and `ZipArchiver::extract` (admin backup restore). The fix is to track cumulative written bytes during stream extraction, not pre-validated declared sizes. Patched in version 2.0.2.

Affected products

  • Getgrav Grav 2.0.1

Timeline

  • 2026-06-25: disclosed: Published to GitHub Advisory Database
  • 2026-09-17: advisory: Updated on GitHub Advisory Database
  • 2026-: patched: Fixed in version 2.0.2

References

Related threats