plone.app.contenttypes has a Denial of Service in File Upload due to excessive filename length
A denial of service vulnerability exists in plone.app.contenttypes when uploading files or images with excessively long filenames. This can cause Plone to become unresponsive and make the UI difficult to use for editing or deleting the content. The issue has been patched in specific versions of plone.app.contenttypes and related fixes are available in plone.app.dexterity. No workarounds are known.
AI Analysis
Technical Summary
The vulnerability in plone.app.contenttypes allows denial of service via file uploads with very large filenames. This causes the Plone instance to become unresponsive or the UI to become unwieldy, impacting availability. The issue affects multiple versions and has been addressed by patches in plone.app.contenttypes versions 5.0.1 (for Plone 6.2), 4.0.10 (for Plone 6.1), and 3.0.12 (for Plone 6.0). Additional related fixes are available in plone.app.dexterity. The vulnerability is tracked as CWE-400 (Uncontrolled Resource Consumption).
Potential Impact
An attacker can cause a denial of service condition by uploading files or images with excessively long filenames, leading to unresponsiveness of the Plone application and difficulty in managing the affected content. There is no impact on confidentiality or integrity reported. The CVSS v3.1 score is 6.5 (medium severity), reflecting network attack vector, low attack complexity, low privileges required, no user interaction, and impact limited to availability.
Mitigation Recommendations
Upgrade plone.app.contenttypes to version 5.0.1 for Plone 6.2, 4.0.10 for Plone 6.1, or 3.0.12 for Plone 6.0 to apply the official patches. Additionally, apply related fixes in plone.app.dexterity as per the referenced advisory. No workarounds are currently known. Since patches are available, applying them is the recommended remediation.
plone.app.contenttypes has a Denial of Service in File Upload due to excessive filename length
Description
A denial of service vulnerability exists in plone.app.contenttypes when uploading files or images with excessively long filenames. This can cause Plone to become unresponsive and make the UI difficult to use for editing or deleting the content. The issue has been patched in specific versions of plone.app.contenttypes and related fixes are available in plone.app.dexterity. No workarounds are known.
CVSS v3.1
Score 6.5medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in plone.app.contenttypes allows denial of service via file uploads with very large filenames. This causes the Plone instance to become unresponsive or the UI to become unwieldy, impacting availability. The issue affects multiple versions and has been addressed by patches in plone.app.contenttypes versions 5.0.1 (for Plone 6.2), 4.0.10 (for Plone 6.1), and 3.0.12 (for Plone 6.0). Additional related fixes are available in plone.app.dexterity. The vulnerability is tracked as CWE-400 (Uncontrolled Resource Consumption).
Potential Impact
An attacker can cause a denial of service condition by uploading files or images with excessively long filenames, leading to unresponsiveness of the Plone application and difficulty in managing the affected content. There is no impact on confidentiality or integrity reported. The CVSS v3.1 score is 6.5 (medium severity), reflecting network attack vector, low attack complexity, low privileges required, no user interaction, and impact limited to availability.
Mitigation Recommendations
Upgrade plone.app.contenttypes to version 5.0.1 for Plone 6.2, 4.0.10 for Plone 6.1, or 3.0.12 for Plone 6.0 to apply the official patches. Additionally, apply related fixes in plone.app.dexterity as per the referenced advisory. No workarounds are currently known. Since patches are available, applying them is the recommended remediation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8pcw-h6w9-h46g
- Osv Schema Version
- 1.4.0
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6ab4be82f7a7c54106f0def1
Added to database: 09/24/2026, 06:09:06 UTC
Last enriched: 09/24/2026, 06:55:03 UTC
Last updated: 09/24/2026, 06:55:03 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.