GHSA-CW7V-45WM-MCF2

Vulnerability from github – Published: 2026-03-27 22:21 – Updated: 2026-04-30 18:33
Withdrawn 2026-04-30 VLAI
Summary
Withdrawn Advisory: Kirby CMS has Persistent DoS via Malformed Image Upload
Details

Duplicate Advisory

This advisory has been withdrawn because it is been determined to not be a vulnerability. This link is maintained to preserve external references.

Original Description

Summary

Kirby CMS through version 5.1.4 allows an authenticated user with Editor permissions to cause a persistent Denial of Service (DoS) via a malformed image upload.

Details

The vulnerability is caused by improper validation of the return value of PHP's getimagesize() function. When a malformed file is uploaded with a valid image extension (e.g., .jpg), the function returns false instead of an expected array.

The application fails to handle this condition properly and proceeds with image processing, resulting in a fatal TypeError. This leads to persistent application crashes when the affected file is accessed.

Impact

  • Persistent Denial of Service (DoS)
  • Affected pages return HTTP 500 errors
  • Requires manual removal of the malformed file to restore functionality
  • Exploitable by authenticated users with Editor permissions

Identifiers

  • CVE-2026-29905

Resources

  • https://github.com/github/advisory-database/pull/7503
  • https://github.com/Stalin-143/CVE-2026-29905
  • https://github.com/getkirby/kirby/releases/tag/5.2.0-rc.1
  • https://www.cve.org/CVERecord?id=CVE-2026-29905
Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "Packagist",
        "name": "getkirby/cms"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "5.2.0-rc.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-29905"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-20",
      "CWE-252"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-03-27T22:21:26Z",
    "nvd_published_at": "2026-03-26T17:16:34Z",
    "severity": "MODERATE"
  },
  "details": "### Duplicate Advisory\nThis advisory has been withdrawn because it is been determined to not be a vulnerability. This link is maintained to preserve external references.\n\n### Original Description\n\n## Summary\n\nKirby CMS through version 5.1.4 allows an authenticated user with Editor permissions to cause a persistent Denial of Service (DoS) via a malformed image upload.\n\n## Details\n\nThe vulnerability is caused by improper validation of the return value of PHP\u0027s `getimagesize()` function. When a malformed file is uploaded with a valid image extension (e.g., `.jpg`), the function returns `false` instead of an expected array.\n\nThe application fails to handle this condition properly and proceeds with image processing, resulting in a fatal `TypeError`. This leads to persistent application crashes when the affected file is accessed.\n\n## Impact\n\n- Persistent Denial of Service (DoS)\n- Affected pages return HTTP 500 errors\n- Requires manual removal of the malformed file to restore functionality\n- Exploitable by authenticated users with Editor permissions\n\n\n## Identifiers\n- CVE-2026-29905\n\n## Resources\n\n- https://github.com/github/advisory-database/pull/7503\n- https://github.com/Stalin-143/CVE-2026-29905\n- https://github.com/getkirby/kirby/releases/tag/5.2.0-rc.1\n- https://www.cve.org/CVERecord?id=CVE-2026-29905",
  "id": "GHSA-cw7v-45wm-mcf2",
  "modified": "2026-04-30T18:33:03Z",
  "published": "2026-03-27T22:21:26Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/Stalin-143/CVE-2026-29905/security/advisories/GHSA-cw7v-45wm-mcf2"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29905"
    },
    {
      "type": "WEB",
      "url": "https://github.com/github/advisory-database/pull/7503"
    },
    {
      "type": "WEB",
      "url": "https://drive.google.com/file/d/1MwvvSYIwnC8kOIzjycGMQZw4d2K2ef8h/view?usp=sharing"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/Stalin-143/CVE-2026-29905"
    },
    {
      "type": "WEB",
      "url": "https://github.com/getkirby/kirby/releases/tag/5.2.0-rc.1"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Withdrawn Advisory: Kirby CMS has Persistent DoS via Malformed Image Upload",
  "withdrawn": "2026-04-30T18:33:03Z"
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…