CVE-2026-72701: Getgrav Grav

Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string comparison with the === operator instead of hash_equals() for CSRF nonce validation. Attackers can measure response timing differences to recover valid nonce values byte-by-byte through multiple requests, weakening CSRF protection below its intended security margin.

Affected products

  • Getgrav Grav: before 2.0.16 (fixed in 2.0.16)

Published 2026-08-25. Last modified 2026-10-08.