THREAT OPS › Threat News › [GHSA] GHSA-8h9x-89f2-m7x3 (medium) — Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer
[GHSA] GHSA-8h9x-89f2-m7x3 (medium) — Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer
GHSA-8h9x-89f2-m7x3 Severity: medium CVE: CVE-2026-61449
Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer
### Summary
The decompression-bomb bound added in 2.0.1 (commit 1c1003c) sums `ZipArchive::statIndex($i)['size']` and rejects an archive whose declared uncompressed total exceeds `system.gpm.archive.max_uncompressed_size` (default 1 GiB) before extracti
MITRE ATT&CK techniques
- Malicious PackageAML.T0011.001
Indicators of compromise
- CVE-2026-61449cve
Original source: https://github.com/advisories/GHSA-8h9x-89f2-m7x3