{"id":"CVE-2026-53653","aliases":["GHSA-4x9g-vw65-vvf9"],"url":"https://o3.security/vulnerability/CVE-2026-53653","summary":"Grav: Unauthenticated denial of service via unbounded image derivative dimensions","details":"Grav is a file-based Web platform. Prior to 1.7.53 and 2.0.0-rc.8, Grav allows an unauthenticated visitor to exhaust server memory and CPU by requesting image derivatives with oversized dimensions through URL query image actions such as forceResize in Grav::fallbackUrl, which passes request parameters to ImageMedium magic actions without a dimension or pixel ceiling. This issue is fixed in versions 1.7.53 and 2.0.0-rc.8.","published":"2026-07-10T16:12:01.576Z","modified":"2026-08-12T03:51:45.285494746Z","cvss":null,"epss":{"score":0.00524,"percentile":0.42048,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"getgrav/grav","fixedVersion":"2.0.0-rc.8"},{"ecosystem":"Packagist","name":"getgrav/grav","fixedVersion":"1.7.53"}],"fix":{"url":"https://github.com/getgrav/grav/commit/d9f9f0369a07ae5c96cde700c7949e1237b29cf6","label":"getgrav/grav@d9f9f03"},"references":[{"type":"WEB","url":"https://github.com/getgrav/grav/releases/tag/1.7.53"},{"type":"WEB","url":"https://github.com/getgrav/grav/releases/tag/2.0.0-rc.8"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53653.json"},{"type":"ADVISORY","url":"https://github.com/getgrav/grav/security/advisories/GHSA-4x9g-vw65-vvf9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53653"},{"type":"FIX","url":"https://github.com/getgrav/grav/commit/d9f9f0369a07ae5c96cde700c7949e1237b29cf6"},{"type":"FIX","url":"https://github.com/getgrav/grav/commit/f4c0f42eea755cedad6f626b342c88d4cba72174"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:45.285494746Z"}}