CVE-2026-29905
Withdrawn Advisory: Kirby CMS has Persistent DoS via Malformed Image Upload
描述
### Duplicate Advisory This advisory has been withdrawn because it is been determined to not be a vulnerability. This link is maintained to preserve external references. ### Original Description ## Summary Kirby CMS through version 5.1.4 allows an authenticated user with Editor permissions to cause a persistent Denial of Service (DoS) via a malformed image upload. ## Details The vulnerability is caused by improper validation of the return value of PHP's `getimagesize()` function. When a malformed file is uploaded with a valid image extension (e.g., `.jpg`), the function returns `false` instead of an expected array. The application fails to handle this condition properly and proceeds with image processing, resulting in a fatal `TypeError`. This leads to persistent application crashes when the affected file is accessed. ## Impact - Persistent Denial of Service (DoS) - Affected pages return HTTP 500 errors - Requires manual removal of the malformed file to restore functionality - Exploitable by authenticated users with Editor permissions ## Identifiers - CVE-2026-29905 ## Resources - https://github.com/github/advisory-database/pull/7503 - https://github.com/Stalin-143/CVE-2026-29905 - https://github.com/getkirby/kirby/releases/tag/5.2.0-rc.1 - https://www.cve.org/CVERecord?id=CVE-2026-29905
如何修補 CVE-2026-29905
要修補 CVE-2026-29905,請將受影響套件升級到下列已修補版本。
- —升級至 5.2.0-rc.1 或更新版本
CVE-2026-29905 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 5.2.0-rc.1