Executive brief
Grav, a popular open-source content management system, is vulnerable to a denial-of-service attack. An authenticated user with permission to edit pages can submit a specially crafted text pattern that forces the server's processor to work indefinitely. This can lead to the entire website becoming unresponsive for all visitors, potentially causing a complete service outage.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in Grav's Twig content sandbox due to the allowlisting of the 'regex_replace' filter and function. The underlying implementation in GravExtension.php passes user-supplied patterns directly to PHP's preg_replace() without complexity validation. If 'security.twig_content.process_enabled' is set to true, an authenticated attacker with page-editing privileges can embed a catastrophic backtracking PCRE pattern in page content. This results in exponential time complexity during processing, exhausting CPU resources and causing a denial of service (DoS) for the web server process. The issue is fixed in version 2.0.4.
Affected products
- getgrav Grav before 2.0.4
Timeline
- 2026-06-29: advisory: Initial GitHub security advisory published
- 2026-07-17: disclosed: NVD publication date