CVE-2026-53653: Grav: Unauthenticated denial of service via unbounded image derivative dimensions
Grav is a file-based Web platform. Prior to 1.7.53 and 2.0.0-rc.8, Grav allows an unauthenticated visitor to exhaust server memory and CPU by requesting image derivatives with oversized dimensions through URL query image actions such as forceResize in Grav::fallbackUrl, which passes request parameters to ImageMedium magic actions without a dimension or pixel ceiling. This issue is fixed in versions 1.7.53 and 2.0.0-rc.8.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Gravto a version that resolves this vulnerability.Fixed in 1.7.53 - Upgrade
Upgrade
Gravto a version that resolves this vulnerability.Fixed in 2.0.0-rc.8
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53653?
CVE-2026-53653 has a risk score of 52, indicating a moderate level of severity.
How do I fix CVE-2026-53653?
To fix CVE-2026-53653, upgrade Grav to version 1.7.53 or 2.0.0-rc.8 or later.
What type of vulnerability is CVE-2026-53653?
CVE-2026-53653 is an unauthenticated denial of service vulnerability.
What can an attacker do with CVE-2026-53653?
An attacker can exhaust server memory and CPU resources by requesting oversized image derivatives.
Which versions of Grav are affected by CVE-2026-53653?
Grav versions prior to 1.7.53 and 2.0.0-rc.8 are affected by CVE-2026-53653.