THREAT OPS › Threat News › [GHSA] GHSA-x5g3-w747-2h8q (critical) — plone.app.portlets vulnerable to denial of service via RSS feed portlet
[GHSA] GHSA-x5g3-w747-2h8q (critical) — plone.app.portlets vulnerable to denial of service via RSS feed portlet
GHSA-x5g3-w747-2h8q Severity: critical CVE: CVE-2026-55248
plone.app.portlets vulnerable to denial of service via RSS feed portlet
### Impact By adding an RSS portlet, and giving this a link to a very large file, a member can cause a denial of service attack, because Plone will use lots of memory. The member could also use different urls to try to get information about the internal network and o
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-55248cve
Original source: https://github.com/advisories/GHSA-x5g3-w747-2h8q