DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-57576: CVE-2026-57576: Application-Level Denial of Service via Uncontrolled Resource Consumption in Plone

CVE-2026-57576: Application-Level Denial of Service via Uncontrolled Resource Consumption in Plone

Vulnerability ID: CVE-2026-57576
CVSS Score: 6.5
Published: 2026-09-23

CVE-2026-57576 is an application-level Denial of Service (DoS) vulnerability in Plone. It resides in the plone.app.dexterity and plone.app.contenttypes packages, allowing authenticated users with content creation permissions to submit excessively long metadata attributes. Because these fields are stored without length limits and subsequently processed by indexing and rendering engines, they trigger complete server resource exhaustion and thread starvation.

TL;DR

Low-privilege authenticated users can trigger an application-level denial of service in Plone by uploading files with extremely long names or saving excessively long titles and descriptions, leading to database indexing bloat and thread crashes.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-400
  • Attack Vector: Network (AV:N)
  • CVSS Base Score: 6.5
  • EPSS Score: 0.00762
  • EPSS Percentile: 53.91%
  • Exploit Status: poc
  • CISA KEV Status: Not Listed

Affected Systems

  • Plone Content Management System
  • plone.app.dexterity
  • plone.app.contenttypes
  • plone.app.dexterity: < 3.2.3 (Fixed in: 3.2.3)
  • plone.app.dexterity: >= 4.0.0, < 4.1.3 (Fixed in: 4.1.3)
  • plone.app.dexterity: = 5.0.0 (Fixed in: 5.0.1)
  • plone.app.contenttypes: < 3.0.12 (Fixed in: 3.0.12)
  • plone.app.contenttypes: >= 4.0.0, < 4.0.10 (Fixed in: 4.0.10)
  • plone.app.contenttypes: = 5.0.0 (Fixed in: 5.0.1)

Code Analysis

Commit: 0d317df

Central config mapping implementation commit

Commit: 2fdceb1

Dexterity behavior schema limits patch

Commit: f359653

Schema field truncation bugfix for filename

Commit: 21bae6e

File and Image metadata limits commit

Commit: 13dc98a

File auto-title truncation subscriber logic commit

Exploit Details

Mitigation Strategies

  • Upgrade plone.app.dexterity and plone.app.contenttypes to patched versions
  • Apply runtime monkey patches to schema definitions
  • Implement WAF rules limiting POST payload/header size
  • Audit and scrub pre-existing oversized fields in the ZODB

Remediation Steps:

  1. Identify the current versions of Plone packages in the buildout configuration.
  2. Update buildout.cfg or requirements.txt to pin plone.app.dexterity to 3.2.3, 4.1.3, or 5.0.1 depending on the release line.
  3. Update plone.app.contenttypes to 3.0.12, 4.0.10, or 5.0.1 depending on the release line.
  4. Run bin/buildout to fetch and install the updated packages.
  5. Restart the Plone/Zope backend servers to load the changes.
  6. Execute a database check to verify no existing objects contain oversized title or description properties.

References


Read the full report for CVE-2026-57576 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)