CVE-2026-29905: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-29905 is a persistent Denial of Service (DoS) vulnerability in Kirby CMS affecting versions through 5.1.4. An authenticated user with 'Editor' permissions can upload a malformed image file to trigger a fatal PHP TypeError, causing persistent application crashes on affected pages. It was disclosed on March 26, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (Github Advisory, Feedly). Note: The GitHub Advisory (GHSA-cw7v-45wm-mcf2) was subsequently withdrawn on April 30, 2026, after it was determined the reported behavior does not constitute a vulnerability, as the Kirby project addressed the underlying issue in version 5.2.0-rc.1 (Github Advisory).

Technical details

The root cause is classified under CWE-20 (Improper Input Validation) and CWE-252 (Unchecked Return Value). PHP's getimagesize() function returns false when passed a malformed or non-image file disguised with a valid image extension (e.g., .jpg); Kirby CMS failed to validate this return value before proceeding with image metadata extraction or thumbnail generation, resulting in a fatal TypeError (Github Advisory). Exploitation requires an authenticated session with at least 'Editor'-level permissions — the attacker uploads the crafted file, and any subsequent access to the affected page or file triggers the crash. The fix in version 5.2.0-rc.1 addresses this by making Kirby\Image\Image::imagesize() return array|false, having Kirby\Image\Dimensions::forImage() return 0×0 for invalid images, and adding an early zero-dimension check in Kirby\Image\Image::isResizable() (Kirby Release).

Impact

Successful exploitation causes persistent HTTP 500 errors on pages or file views that attempt to process the malformed upload, effectively rendering those resources unavailable until the file is manually removed by an administrator. There is no confidentiality or integrity impact — the vulnerability is limited to availability. Because the DoS condition persists until manual remediation, even a single malicious Editor-level user can cause sustained disruption to site functionality (Github Advisory, Feedly).

Exploitability

No confirmed working exploit code exists; the GitHub repository attributed to the researcher (Stalin-143/CVE-2026-29905) contains only documentation and CVE disclosure tables with no runnable exploit code or reproduction steps (Feedly). There is no evidence of in-the-wild exploitation, no threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.034% (0.000340), indicating a very low probability of exploitation in the near term (Github Advisory). The advisory was also formally withdrawn on April 30, 2026, after review determined the behavior does not meet the threshold of a security vulnerability (Github Advisory).

Exploitation steps

  1. Authenticate: Log in to the Kirby CMS Panel with an account that has at least 'Editor' permissions.
  2. Craft malformed file: Create a file with a valid image extension (e.g., malicious.jpg) that contains non-image binary data, causing PHP's getimagesize() to return false instead of an array.
  3. Upload the file: Use the Kirby Panel's file upload interface to upload the crafted file to a page or files section.
  4. Trigger the crash: Navigate to or cause the application to process the uploaded file (e.g., by visiting the page, accessing the file URL, or triggering thumbnail generation). The unhandled false return from getimagesize() causes a fatal TypeError.
  5. Persistent DoS: The affected page or file view now returns HTTP 500 errors for all users until an administrator manually removes the malformed file from the server (Github Advisory, Kirby Release).

Indicators of compromise

  • Logs: PHP fatal error logs or web server error logs showing TypeError exceptions originating from Kirby\Image\Image::imagesize(), Kirby\Image\Dimensions::forImage(), or related image processing methods.
  • File System: Presence of files with image extensions (.jpg, .png, .gif, etc.) in Kirby content directories that are not valid image files (detectable via file command or getimagesize() returning false).
  • Application Behavior: Specific pages or file views consistently returning HTTP 500 errors, particularly after a recent file upload by an Editor-level user.
  • Logs: Kirby CMS error logs showing repeated 500 responses tied to image metadata or thumbnail generation routines (Github Advisory).

Mitigation and workarounds

Upgrade Kirby CMS to version 5.2.0-rc.1 or later, which handles malformed images gracefully by returning array|false from imagesize() and checking for zero dimensions before processing (Kirby Release). As a workaround prior to patching, restrict the 'Editor' role to only fully trusted users, and implement server-side validation of uploaded files to verify actual image format (e.g., using MIME type detection) before allowing processing. Monitor PHP and web server error logs for TypeError exceptions in image processing code as an indicator of exploitation attempts. Note that the GitHub Advisory for this CVE was withdrawn on April 30, 2026, as the behavior was determined not to be a security vulnerability after the fix was incorporated (Github Advisory).

Community reactions

The GitHub Advisory (GHSA-cw7v-45wm-mcf2) was withdrawn on April 30, 2026, after the Kirby project and GitHub reviewers determined the reported behavior does not constitute a security vulnerability. The Kirby 5.2.0-rc.1 release notes credit the researcher (Stalin-143 / 0x5t4l1n) for the report and describe the fix as "Handle malformed images gracefully on upload," indicating the project treated it as a robustness improvement rather than a security issue (Kirby Release, Github Advisory). No significant broader media coverage or notable security community commentary was identified.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management