CVE-2026-53653 Details
Description
Grav is a file-based Web platform. Prior to 1.7.53 and 2.0.0-rc.8, Grav allows an unauthenticated visitor to exhaust server memory and CPU by requesting image derivatives with oversized dimensions through URL query image actions such as forceResize in Grav::fallbackUrl, which passes request parameters to ImageMedium magic actions without a dimension or pixel ceiling. This issue is fixed in versions 1.7.53 and 2.0.0-rc.8.
A denial-of-service vulnerability has been identified in Grav, a file-based web platform, in versions prior to 1.7.53 and 2.0.0-rc.8. The issue allows an unauthenticated visitor to exhaust server memory and CPU resources by requesting image derivatives with excessively large dimensions. This is done through URL query image actions, such as 'forceResize', which are processed without any restrictions on size. As a result, the server can be overwhelmed, causing significant performance degradation.
Users can update to Grav version 1.7.53 or 2.0.0-rc.8, both of which include the necessary fix. Instructions for downloading these versions are available on the Grav GitHub Releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 10, 2026CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/getgrav/grav/commit/d9f9f0369a07ae5c96cde700c7949e1237b29cf6 | [email protected] | Source CodeVendor |
| https://github.com/getgrav/grav/commit/f4c0f42eea755cedad6f626b342c88d4cba72174 | [email protected] | Source CodeVendor |
| https://github.com/getgrav/grav/releases/tag/1.7.53 | [email protected] | Release NotesVendor |
| https://github.com/getgrav/grav/releases/tag/2.0.0-rc.8 | [email protected] | Release NotesVendor |
| https://github.com/getgrav/grav/security/advisories/GHSA-4x9g-vw65-vvf9 | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Grav | ~1.7 ~2.0.0-rc (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | New CVE Received | [email protected] |
Volerion