THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-92hv-j533-69wc (low) — Wagtail: Identification of documents by SHA1 hash

[GHSA] GHSA-92hv-j533-69wc (low) — Wagtail: Identification of documents by SHA1 hash

highgithub_advisoriesPublished 2026-08-20

GHSA-92hv-j533-69wc Severity: low CVE: None

Wagtail: Identification of documents by SHA1 hash

### Impact By passing specific HTTP headers to the document serve URL endpoint, an attacker was able to determine whether a document with a given ID matched a specified SHA1 hash, regardless of any permission restrictions on the document or knowing its filename. This could allow an attacker to determine

Indicators of compromise

Original source: https://github.com/advisories/GHSA-92hv-j533-69wc