THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-vwg3-w8w3-pc79 (high) — Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems

[GHSA] GHSA-vwg3-w8w3-pc79 (high) — Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems

medgithub_advisoriesPublished 2026-08-19

GHSA-vwg3-w8w3-pc79 Severity: high CVE: CVE-2026-62673

Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems

## Summary

The default `.htaccess` shipped with Grav (and the reference `webserver-configs/htaccess.txt`) contains security rules that block direct HTTP access to sensitive file types (`.yaml`, `.yml`, `.php`, `.json`, `.twig`, etc.) under `user/`

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-vwg3-w8w3-pc79