{"id":"GHSA-v626-428r-43p8","summary":"Duplicate Advisory: Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer","details":"### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-8h9x-89f2-m7x3. This link is maintained to preserve external references.\n\n### Original Description\nGrav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\\Installer. The size bound introduced in 2.0.1 sums the uncompressed size declared in each entry's ZIP central-directory header (ZipArchive::statIndex()['size']) and rejects archives exceeding system.gpm.archive.max_uncompressed_size before extraction. Because this declared size is attacker-forgeable and is not cross-checked against the actual inflated stream, a crafted archive declaring tiny per-entry sizes passes the cap while extractTo() writes the real, much larger content, filling disk or exhausting inodes. The archive must be supplied by a package source or admin upload (admin/operator trust). Fixed in 2.0.2. This is an incomplete fix for GHSA-928x-9mpw-8h56.","modified":"2026-09-17T15:00:05.906568665Z","published":"2026-07-15T12:32:04Z","withdrawn":"2026-09-17T14:53:18Z","database_specific":{"cwe_ids":["CWE-409"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-17T14:53:18Z","nvd_published_at":"2026-07-15T12:18:19Z"},"references":[{"type":"WEB","url":"https://github.com/getgrav/grav/security/advisories/GHSA-8h9x-89f2-m7x3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61449"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/grav-before-decompression-bomb-via-forged-zip-size"}],"affected":[{"package":{"name":"getgrav/grav","ecosystem":"Packagist","purl":"pkg:composer/getgrav/grav"},"versions":["2.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-v626-428r-43p8/GHSA-v626-428r-43p8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}