CVE-2026-53653: Getgrav Grav

High severity, CVSS 8.7. EPSS: 0.5% chance of exploitation in the next 30 days.

Grav is a file-based Web platform. Prior to 1.7.53 and 2.0.0-rc.8, Grav allows an unauthenticated visitor to exhaust server memory and CPU by requesting image derivatives with oversized dimensions through URL query image actions such as forceResize in Grav::fallbackUrl, which passes request parameters to ImageMedium magic actions without a dimension or pixel ceiling. This issue is fixed in versions 1.7.53 and 2.0.0-rc.8.

Affected products

  • Getgrav Grav: from 2.0.0-beta.1, before 2.0.0-rc.8 (fixed in 2.0.0-rc.8); before 1.7.53 (fixed in 1.7.53)

Published 2026-07-10. Last modified 2026-07-10.