Answer in brief
CVE-2026-62672 records a Medium severity (CVSS 6.0) vulnerability in Grav < 2.0.4 ReDoS via regex_replace in Sandbox. The current sources do not mark it as known exploited. The current feed maps getgrav/grav (composer), getgrav/grav (generic), getgrav/grav (generic), getgrav/grav (packagist). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 6.0. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps getgrav/grav (composer), getgrav/grav (generic), getgrav/grav (generic), getgrav/grav (packagist). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| getgrav/gravcomposer | <2.0.4 | 2.0.4 |
| getgrav/gravgeneric | <2.0.4 | 2.0.4 |
| getgrav/gravgeneric | >=0 <2.0.4 | 2.0.4 |
| getgrav/gravpackagist | >=0 <2.0.4 | 2.0.4 |
Published upstream
Jul 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 19, 2026
Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and function, which are allowlisted in the Twig content sandbox. When Twig processing in page content is enabled (security.twig_content.process_enabled: true, disabled by default), an authenticated page editor can supply a catastrophically backtracking PCRE pattern that is passed directly to PHP's preg_replace(), causing unbounded CPU consumption and denial of service to the web server process.
Quoted source text, attributed separately from HOL analysis.