Junglewise Threat Intelligence

CVE-2026-62237: Grav ReDoS in Twig sandbox regex_replace filter

CVE-2026-62237 · Severity: medium · CVSS 6.5 · Published 2026-07-17

Technologies: Grav, Getgrav Grav, getgrav/grav (Packagist). Vendors: Grav, Getgrav, Packagist.

Executive brief

Grav, a popular open-source content management system, is vulnerable to a denial-of-service attack. An authenticated user with permission to edit pages can submit a specially crafted text pattern that forces the server's processor to work indefinitely. This can lead to the entire website becoming unresponsive for all visitors, potentially causing a complete service outage.

Technical details

A Regular Expression Denial of Service (ReDoS) vulnerability exists in Grav's Twig content sandbox due to the allowlisting of the 'regex_replace' filter and function. The underlying implementation in GravExtension.php passes user-supplied patterns directly to PHP's preg_replace() without complexity validation. If 'security.twig_content.process_enabled' is set to true, an authenticated attacker with page-editing privileges can embed a catastrophic backtracking PCRE pattern in page content. This results in exponential time complexity during processing, exhausting CPU resources and causing a denial of service (DoS) for the web server process. The issue is fixed in version 2.0.4.

Affected products

  • getgrav Grav before 2.0.4

Timeline

  • 2026-06-29: advisory: Initial GitHub security advisory published
  • 2026-07-17: disclosed: NVD publication date

References

Related threats