DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

GHSA-8PCW-H6W9-H46G: GHSA-8PCW-H6W9-H46G: Denial of Service via Uncontrolled Resource Consumption in plone.app.contenttypes

GHSA-8PCW-H6W9-H46G: Denial of Service via Uncontrolled Resource Consumption in plone.app.contenttypes

Vulnerability ID: GHSA-8PCW-H6W9-H46G
CVSS Score: 6.5
Published: 2026-09-23

An uncontrolled resource consumption vulnerability in plone.app.contenttypes allows authenticated users to trigger application-level denial of service via oversized filename metadata in file uploads.

TL;DR

An input validation flaw in plone.app.contenttypes allows authenticated users to cause a denial of service by uploading files with excessively long filenames, leading to database bloat, catalog indexing delays, and CPU/memory exhaustion.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-400 (Uncontrolled Resource Consumption)
  • Alternative CWE: CWE-20 (Improper Input Validation)
  • Attack Vector: Network (HTTP Multipart POST)
  • CVSS v3.1: 6.5 / 7.5 (Depending on anonymous upload privileges)
  • Impact: Denial of Service (CPU & Memory Exhaustion)
  • Exploit Status: PoC / Replicated
  • KEV Status: Not Listed

Affected Systems

  • Plone Content Management System (CMS) with plone.app.contenttypes package
  • plone.app.contenttypes: < 3.0.12 (Fixed in: 3.0.12)
  • plone.app.contenttypes: >= 4.0.0, < 4.0.10 (Fixed in: 4.0.10)
  • plone.app.contenttypes: >= 5.0.0, < 5.0.1 (Fixed in: 5.0.1)

Code Analysis

Commit: 13dc98a

Fix DoS vulnerability in event subscriber by truncating automatic title assignments to MAX_TITLE_LENGTH.

Commit: 21bae6e

Enforce schema-level max_length restrictions on title and description elements.

Commit: 639c061

Update plone.app.contenttypes file schema with validation boundary constraints.

Commit: 7bb03e8

Update plone.app.contenttypes image schema with validation boundary constraints.

Commit: bed1547

Consolidate and verify event subscriber safeguards for automatic metadata creation.

Mitigation Strategies

  • Enforce strict length limits on filename attributes in multipart upload requests at the WAF level.
  • Implement a custom event subscriber to truncate existing content object titles that exceed safe limits.
  • Disable anonymous file upload privileges on public-facing Plone folders.

Remediation Steps:

  1. Upgrade plone.app.contenttypes to version 3.0.12, 4.0.10, or 5.0.1 based on your Plone release line.
  2. Run a diagnostic script via the Zope interpreter to scan the database and truncate existing oversize title/description properties.
  3. Verify that schema XML files enforce max_length configurations on Title and Description fields.

References


Read the full report for GHSA-8PCW-H6W9-H46G on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)