CVE-2026-57576

medium

Description

plone.app.dexterity is a content-type system for the Plone content management system, and plone.app.contenttypes provides Plone’s Dexterity-based content types. Plone.app.dexterity versions through 3.2.2, 4.0.0 through 4.1.2, and 5.0.0, and plone.app.contenttypes versions through 3.0.11, 4.0.0 through 4.0.9, and 5.0.0 are vulnerable to denial of service because an authenticated user can create content with excessively long titles, descriptions, or uploaded-file names, causing Plone to become unresponsive and potentially making the resulting content difficult to edit or delete. The vulnerability is patched in plone.app.dexterity versions 3.2.3, 4.1.3, and 5.0.1, and in plone.app.contenttypes versions 3.0.12, 4.0.10, and 5.0.1.

References

https://github.com/plone/plone.app.dexterity/security/advisories/GHSA-5426-92w4-wvhv

https://github.com/plone/plone.app.dexterity/commit/fb45bfdb18f1dfb3ed55e477947a3df9a6ee9e20

https://github.com/plone/plone.app.dexterity/commit/f3596538cf7670bb8bc27b0dfa0b1da41c8b8a3a

https://github.com/plone/plone.app.dexterity/commit/cbcef731c0882146b9bf30688cdc639d879878fb

https://github.com/plone/plone.app.dexterity/commit/411689047f9a3521899ae6992a9b0efbd0592a8f

https://github.com/plone/plone.app.dexterity/commit/2fdceb120ca86682a408f3a14753cfcf5126d9d9

https://github.com/plone/plone.app.dexterity/commit/0d317df663823445200d0569a66a95b7e4a9c50d

https://github.com/plone/plone.app.contenttypes/security/advisories/GHSA-8pcw-h6w9-h46g

https://github.com/plone/plone.app.contenttypes/commit/bed1547d4f8b1fc995f2c76f30ba5f20276a8ad6

https://github.com/plone/plone.app.contenttypes/commit/7bb03e8ec6c6bd0e645f445b0755e85a51afb158

https://github.com/plone/plone.app.contenttypes/commit/639c0619f371df578e69ec94e5ca98e60fd6ed58

https://github.com/plone/plone.app.contenttypes/commit/21bae6ebe424689eeac9a5884fc0da35f4944e63

https://github.com/plone/plone.app.contenttypes/commit/13dc98a578341aac24a1e65fd9bc7ac8a07d168a

Details

Source: Mitre, NVD

Published: 2026-09-22

Updated: 2026-09-23

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00762