Vulnerability Description
Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and function, which are allowlisted in the Twig content sandbox. When Twig processing in page content is enabled (security.twig_content.process_enabled: true, disabled by default), an authenticated page editor can supply a catastrophically backtracking PCRE pattern that is passed directly to PHP's preg_replace(), causing unbounded CPU consumption and denial of service to the web server process.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/getgrav/grav/security/advisories/GHSA-37f3-6p89-6qr9
- https://www.vulncheck.com/advisories/grav-redos-via-regex-replace-in-sandbox
- https://github.com/getgrav/grav/security/advisories/GHSA-37f3-6p89-6qr9
FAQ
What is CVE-2026-62237?
CVE-2026-62237 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and function, which are allowlisted in the Twig content sandbox. When Twig processin...
How severe is CVE-2026-62237?
CVE-2026-62237 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-62237?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.