CVE-2026-61455: Getgrav Grav

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Grav before 2.0.1 contains a decompression bomb vulnerability in ZipArchiver::extract() that lacks limits on uncompressed size, file count, and nesting depth. Attackers can supply a crafted ZIP archive that expands to fill available disk space, causing denial of service by exhausting storage resources.

Affected products

  • Getgrav Grav: before 2.0.1 (fixed in 2.0.1)

Published 2026-07-10. Last modified 2026-10-08.