Evidence used
- No CISA KEV confirmation is currently recorded.
- EPSS is 0.44% for the current model date.
BlackTreeCVE Intelligenceplone · plone.app.portlets
Official source article: GitHub GHSA-X5G3-W747-2H8Q ↗. Check the applicable product and release in the original source.
Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.
These OSV and GitHub advisory ranges apply only to the named package and ecosystem. A listed fixed version is not a universal product patch or proof that an update is installed.
| Ecosystem and package | Affected range | First fixed version | Evidence |
|---|---|---|---|
| PyPIplone-app-portlets | ECOSYSTEM: introduced 7.0.0; fixed 7.0.2 | 7.0.2 | OSV record ↗aggregator derived · 10 Sep 2026 |
| PyPIplone-app-portlets | ECOSYSTEM: introduced 6.0.0; fixed 6.0.4 | 6.0.4 | OSV record ↗aggregator derived · 10 Sep 2026 |
| PyPIplone-app-portlets | ECOSYSTEM: introduced 0; fixed 5.0.8 | 5.0.8 | OSV record ↗aggregator derived · 10 Sep 2026 |
| PyPIplone-app-portlets | ECOSYSTEM: introduced 0; fixed 5.0.8; introduced 6.0.0; fixed 6.0.4; introduced 7.0.0; fixed 7.0.2 | 5.0.8, 6.0.4, 7.0.2 | OSV record ↗source linked ecosystem record · 10 Sep 2026 |
| pipplone.app.portlets | >= 7.0.0, <= 7.0.1 | 7.0.2 | GitHub advisory ↗upstream repository advisory · 28 Aug 2026 |
| pipplone.app.portlets | >= 6.0.0, < 6.0.4 | 6.0.4 | GitHub advisory ↗upstream repository advisory · 28 Aug 2026 |
| pipplone.app.portlets | < 5.0.8 | 5.0.8 | GitHub advisory ↗upstream repository advisory · 28 Aug 2026 |
Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.
Fix not verifiedplone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior to 5.0.8, 6.0.4, and 7.0.2, a member who can add an RSS portlet can set its feed URL to a very large response, causing src/plone/app/portlets/portlets/rss.py to download and retain excessive data in memory and deny service. The same RSS URL handling accepts internal hosts, IP addresses, single-word domains, and explicit ports, allowing server-side requests that can probe internal network services and open ports. A malicious feed item can also supply a JavaScript URL that is retained as the item link and can execute script when used by a victim. The affected logic includes _rss_feed_url_validator, _normal_url_validator, RSSFeed._retrieveFeed, RSSFeed._buildItemDict, and the FEED_DATA in-memory cache. This issue is fixed in versions 5.0.8, 6.0.4, and 7.0.2.
plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior to 5.0.8, 6.0.4, and 7.0.2, a member who can add an RSS portlet can set its feed URL to a very large response, causing src/plone/app/portlets/portlets/rss.py to download and retain excessive data in memory and deny service. The same RSS URL handling accepts internal hosts, IP addresses, single-word domains, and explicit ports, allowing server-side requests that can probe internal network services and open ports. A malicious feed item can also supply a JavaScript URL that is retained as the item link and can execute script when used by a victim. The affected logic includes _rss_feed_url_validator, _normal_url_validator, RSSFeed._retrieveFeed, RSSFeed._buildItemDict, and the FEED_DATA in-memory cache. This issue is fixed in versions 5.0.8, 6.0.4, and 7.0.2.
The product does not properly control the allocation and maintenance of a limited resource.
An attacker operating through a network path may attempt exploitation with low privileges. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.
plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior to 5.0.8, 6.0.4, and 7.0.2, a member who can add an RSS portlet can set its feed URL to a very large response, causing src/plone/app/portlets/portlets/rss.py to download and retain excessive data in memory and deny service. The same RSS URL handling accepts internal hosts, IP addresses, single-word domains, and explicit ports, allowing server-side requests that can probe internal network services and open ports. A malicious feed item can also supply a JavaScript URL that is retained as the item link and can execute script when used by a victim. The affected logic includes _rss_feed_url_validator, _normal_url_validator, RSSFeed._retrieveFeed, RSSFeed._buildItemDict, and the FEED_DATA in-memory cache. This issue is fixed in versions 5.0.8, 6.0.4, and 7.0.2.
The product does not properly control the allocation and maintenance of a limited resource.
An attacker operating through a network path may attempt exploitation with low privileges. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.
CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.
No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.
No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.
CWE-400: Uncontrolled Resource Consumption. The product does not properly control the allocation and maintenance of a limited resource.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:HCommon Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.
Operational remediation based on structured source evidence.
Published 28 Aug 2026 · Last source change 28 Aug 2026, 20:35 UTC · CWE-400 · Uncontrolled Resource Consumption
Core structured fields are present and their contributing authorities are shown above.