CVE-2026-62672: Grav: Authenticated ReDoS via regex_replace in Twig Sandbox
(updated )
The regex_replace filter and function are allowlisted in Grav’s Twig content sandbox. When Twig processing in page content is enabled security.twig_content.process_enabled: true, authenticated page editors can supply a catastrophically backtracking PCRE pattern, causing unbounded CPU consumption and denying service to the entire web server process.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-62672 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →