THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-x5g3-w747-2h8q (critical) — plone.app.portlets vulnerable to denial of service via RSS feed portlet

[GHSA] GHSA-x5g3-w747-2h8q (critical) — plone.app.portlets vulnerable to denial of service via RSS feed portlet

medgithub_advisoriesPublished 2026-08-28

GHSA-x5g3-w747-2h8q Severity: critical CVE: CVE-2026-55248

plone.app.portlets vulnerable to denial of service via RSS feed portlet

### Impact By adding an RSS portlet, and giving this a link to a very large file, a member can cause a denial of service attack, because Plone will use lots of memory. The member could also use different urls to try to get information about the internal network and o

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-x5g3-w747-2h8q