GHSA-v626-428r-43p8

Suggest an improvement
Source
https://github.com/advisories/GHSA-v626-428r-43p8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-v626-428r-43p8/GHSA-v626-428r-43p8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-v626-428r-43p8
Withdrawn
2026-09-17T14:53:18Z
Published
2026-07-15T12:32:04Z
Modified
2026-09-17T15:00:05Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Duplicate Advisory: Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-8h9x-89f2-m7x3. This link is maintained to preserve external references.

Original Description

Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in 2.0.1 sums the uncompressed size declared in each entry's ZIP central-directory header (ZipArchive::statIndex()['size']) and rejects archives exceeding system.gpm.archive.max_uncompressed_size before extraction. Because this declared size is attacker-forgeable and is not cross-checked against the actual inflated stream, a crafted archive declaring tiny per-entry sizes passes the cap while extractTo() writes the real, much larger content, filling disk or exhausting inodes. The archive must be supplied by a package source or admin upload (admin/operator trust). Fixed in 2.0.2. This is an incomplete fix for GHSA-928x-9mpw-8h56.

Database specific
{
    "cwe_ids": [
        "CWE-409"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-17T14:53:18Z",
    "nvd_published_at": "2026-07-15T12:18:19Z",
    "severity": "HIGH"
}
References

Affected packages

Packagist / getgrav/grav

Package

Name
getgrav/grav
Purl
pkg:composer/getgrav/grav

Affected ranges

Affected versions

2.*
2.0.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-v626-428r-43p8/GHSA-v626-428r-43p8.json"