
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-29905 is a persistent Denial of Service (DoS) vulnerability in Kirby CMS affecting versions through 5.1.4. An authenticated user with 'Editor' permissions can upload a malformed image file to trigger a fatal PHP TypeError, causing persistent application crashes on affected pages. It was disclosed on March 26, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (Github Advisory, Feedly). Note: The GitHub Advisory (GHSA-cw7v-45wm-mcf2) was subsequently withdrawn on April 30, 2026, after it was determined the reported behavior does not constitute a vulnerability, as the Kirby project addressed the underlying issue in version 5.2.0-rc.1 (Github Advisory).
The root cause is classified under CWE-20 (Improper Input Validation) and CWE-252 (Unchecked Return Value). PHP's getimagesize() function returns false when passed a malformed or non-image file disguised with a valid image extension (e.g., .jpg); Kirby CMS failed to validate this return value before proceeding with image metadata extraction or thumbnail generation, resulting in a fatal TypeError (Github Advisory). Exploitation requires an authenticated session with at least 'Editor'-level permissions — the attacker uploads the crafted file, and any subsequent access to the affected page or file triggers the crash. The fix in version 5.2.0-rc.1 addresses this by making Kirby\Image\Image::imagesize() return array|false, having Kirby\Image\Dimensions::forImage() return 0×0 for invalid images, and adding an early zero-dimension check in Kirby\Image\Image::isResizable() (Kirby Release).
Successful exploitation causes persistent HTTP 500 errors on pages or file views that attempt to process the malformed upload, effectively rendering those resources unavailable until the file is manually removed by an administrator. There is no confidentiality or integrity impact — the vulnerability is limited to availability. Because the DoS condition persists until manual remediation, even a single malicious Editor-level user can cause sustained disruption to site functionality (Github Advisory, Feedly).
No confirmed working exploit code exists; the GitHub repository attributed to the researcher (Stalin-143/CVE-2026-29905) contains only documentation and CVE disclosure tables with no runnable exploit code or reproduction steps (Feedly). There is no evidence of in-the-wild exploitation, no threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.034% (0.000340), indicating a very low probability of exploitation in the near term (Github Advisory). The advisory was also formally withdrawn on April 30, 2026, after review determined the behavior does not meet the threshold of a security vulnerability (Github Advisory).
malicious.jpg) that contains non-image binary data, causing PHP's getimagesize() to return false instead of an array.false return from getimagesize() causes a fatal TypeError.TypeError exceptions originating from Kirby\Image\Image::imagesize(), Kirby\Image\Dimensions::forImage(), or related image processing methods..jpg, .png, .gif, etc.) in Kirby content directories that are not valid image files (detectable via file command or getimagesize() returning false).Upgrade Kirby CMS to version 5.2.0-rc.1 or later, which handles malformed images gracefully by returning array|false from imagesize() and checking for zero dimensions before processing (Kirby Release). As a workaround prior to patching, restrict the 'Editor' role to only fully trusted users, and implement server-side validation of uploaded files to verify actual image format (e.g., using MIME type detection) before allowing processing. Monitor PHP and web server error logs for TypeError exceptions in image processing code as an indicator of exploitation attempts. Note that the GitHub Advisory for this CVE was withdrawn on April 30, 2026, as the behavior was determined not to be a security vulnerability after the fix was incorporated (Github Advisory).
The GitHub Advisory (GHSA-cw7v-45wm-mcf2) was withdrawn on April 30, 2026, after the Kirby project and GitHub reviewers determined the reported behavior does not constitute a security vulnerability. The Kirby 5.2.0-rc.1 release notes credit the researcher (Stalin-143 / 0x5t4l1n) for the report and describe the fix as "Handle malformed images gracefully on upload," indicating the project treated it as a robustness improvement rather than a security issue (Kirby Release, Github Advisory). No significant broader media coverage or notable security community commentary was identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."