GHSA-8PCW-H6W9-H46G: Denial of Service via Uncontrolled Resource Consumption in plone.app.contenttypes
Vulnerability ID: GHSA-8PCW-H6W9-H46G
CVSS Score: 6.5
Published: 2026-09-23
An uncontrolled resource consumption vulnerability in plone.app.contenttypes allows authenticated users to trigger application-level denial of service via oversized filename metadata in file uploads.
TL;DR
An input validation flaw in plone.app.contenttypes allows authenticated users to cause a denial of service by uploading files with excessively long filenames, leading to database bloat, catalog indexing delays, and CPU/memory exhaustion.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-400 (Uncontrolled Resource Consumption)
- Alternative CWE: CWE-20 (Improper Input Validation)
- Attack Vector: Network (HTTP Multipart POST)
- CVSS v3.1: 6.5 / 7.5 (Depending on anonymous upload privileges)
- Impact: Denial of Service (CPU & Memory Exhaustion)
- Exploit Status: PoC / Replicated
- KEV Status: Not Listed
Affected Systems
- Plone Content Management System (CMS) with plone.app.contenttypes package
-
plone.app.contenttypes: < 3.0.12 (Fixed in:
3.0.12) -
plone.app.contenttypes: >= 4.0.0, < 4.0.10 (Fixed in:
4.0.10) -
plone.app.contenttypes: >= 5.0.0, < 5.0.1 (Fixed in:
5.0.1)
Code Analysis
Commit: 13dc98a
Fix DoS vulnerability in event subscriber by truncating automatic title assignments to MAX_TITLE_LENGTH.
Commit: 21bae6e
Enforce schema-level max_length restrictions on title and description elements.
Commit: 639c061
Update plone.app.contenttypes file schema with validation boundary constraints.
Commit: 7bb03e8
Update plone.app.contenttypes image schema with validation boundary constraints.
Commit: bed1547
Consolidate and verify event subscriber safeguards for automatic metadata creation.
Mitigation Strategies
- Enforce strict length limits on filename attributes in multipart upload requests at the WAF level.
- Implement a custom event subscriber to truncate existing content object titles that exceed safe limits.
- Disable anonymous file upload privileges on public-facing Plone folders.
Remediation Steps:
- Upgrade plone.app.contenttypes to version 3.0.12, 4.0.10, or 5.0.1 based on your Plone release line.
- Run a diagnostic script via the Zope interpreter to scan the database and truncate existing oversize title/description properties.
- Verify that schema XML files enforce max_length configurations on Title and Description fields.
References
- GHSA-8PCW-H6W9-H46G Advisory
- GitHub Pull Request #744
- plone.app.contenttypes v3.0.12 Release
- plone.app.contenttypes v4.0.10 Release
- plone.app.contenttypes v5.0.1 Release
Read the full report for GHSA-8PCW-H6W9-H46G on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)