Executive brief
Grav, a popular content management system, contains a flaw in how it handles compressed ZIP files. An attacker can upload a specially crafted, highly compressed file (known as a 'zip bomb') that, when opened by the system, expands to an enormous size. This can completely fill the server's storage space, potentially crashing the website and preventing legitimate operations.
Technical details
A decompression bomb (CWE-409) vulnerability exists in the ZipArchiver::extract() method of Grav. While a similar component (Installer::unZip()) was previously patched with resource limits, the ZipArchiver path lacks validation for uncompressed file size, total file count, and directory nesting depth. An authenticated attacker with the ability to trigger ZIP extraction via third-party plugins or custom code using the Archiver abstraction can provide a malicious archive that exhausts disk space. This results in a Denial of Service (DoS) condition. The issue is resolved in version 2.0.1 by implementing the same archiveLimits() validation used in other parts of the codebase.
Affected products
- getgrav Grav < 2.0.1
Timeline
- 2026-06-24: advisory: GitHub Security Advisory published by vendor
- 2026-07-10: disclosed: CVE published to NVD