OSV 1.4.0 · github-reviewed · 修改于 2026-09-02 22:50
发布时间
2026-09-02 22:50
GitHub 审查时间
2026-09-02 22:50
NVD 发布时间
2026-08-20 00:18
源文件
advisories/github-reviewed/2026/09/GHSA-37f3-6p89-6qr9/GHSA-37f3-6p89-6qr9.json
The regex_replace filter and function are allowlisted in Grav's Twig content sandbox. When Twig processing in page content is enabled security.twig_content.process_enabled: true, authenticated page editors can supply a catastrophically backtracking PCRE pattern, causing unbounded CPU consumption and denying service to the entire web server process.
The Twig sandbox allowlists, defined in system/config/security.yaml, explicitly include regex_replace in both the filter and function permission lists:
Source: system/config/security.yaml
twig_sandbox:
allowed_filters:
# ...
- regex_replace # user-controlled pattern allowed in sandbox
allowed_functions:
# ...
- regex_replace # same
The underlying implementation passes the caller-controlled $pattern directly into PHP's preg_replace() without any pattern complexity validation:
Source: system/src/Grav/Common/Twig/Extension/GravExtension.php:1317-1319
public function regexReplace($subject, $pattern, $replace, $limit = -1)
{
return preg_replace($pattern, $replace, $subject, $limit);
}
When twig_content.process_enabled is true, page body content is sandboxed but can use any allowlisted filter. An editor who embeds a catastrophic backtracking pattern causes the PCRE engine to enter exponential time complexity, consuming 100% CPU until the PHP process is killed or the request times out.
Conditions required:
security.twig_content.process_enabled: true (opt-in, false by default on fresh 2.0 installs)security.twig_sandbox.enabled: true (default) - the function is reachable under sandboxConfiguration prerequisite - enable Twig in content:
# user/config/security.yaml
twig_content:
process_enabled: true
Payload — embed in any Grav page body with process: { twig: true } in frontmatter:
---
title: Test
process:
twig: true
---
{{ 'aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaab'|regex_replace('/^(a+)+$/', '') }}
Or as a function call in a page where the editor has Twig access:
{{ regex_replace('aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaab', '/^(a+)+$/', '') }}
Result: The PHP-FPM worker (or CLI server process) enters catastrophic PCRE backtracking. On a 2 GHz host, a 32-character string with the above pattern will exhaust one CPU core for seconds to minutes. With a slightly longer string, the time grows exponentially.
Vulnerability type: Regular Expression Denial of Service - ReDoS
Who is impacted: Server availability. Any Grav installation where:
twig_content.process_enabled: trueAn attacker with page-edit access can render the site unresponsive for all visitors by publishing a page with a catastrophic regex. On single-worker PHP configurations this is a complete outage. On multi-worker setups, multiple concurrent page renders of the malicious page can saturate all workers.