CVE-2026-54260 MEDIUM

CVE-2026-54260: Wagtail: Denial of service via unbounded filter specs in the image preview

Vendor Wagtail
Product wagtail
Weakness CWE-400
Published July 1, 2026
Last update July 2, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

What the vulnerability does

01Description

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, an authenticated admin user can trigger expensive rendition processing with purposefully crafted filter specs resulting in potentially service degradation. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. This issue has been fixed in versions 7.0.8, 7.3.3, and 7.4.2.

Key dates

02Disclosure timeline

July 1, 2026 CVE published
July 2, 2026 Record updated