CVE-2026-57576
Received Received - Intake

Denial of Service in Plone.app.dexterity and Plone.app.contenttypes

Vulnerability report for CVE-2026-57576, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: GitHub, Inc.

Description

plone.app.dexterity is a content-type system for the Plone content management system, and plone.app.contenttypes provides Plone’s Dexterity-based content types. Plone.app.dexterity versions through 3.2.2, 4.0.0 through 4.1.2, and 5.0.0, and plone.app.contenttypes versions through 3.0.11, 4.0.0 through 4.0.9, and 5.0.0 are vulnerable to denial of service because an authenticated user can create content with excessively long titles, descriptions, or uploaded-file names, causing Plone to become unresponsive and potentially making the resulting content difficult to edit or delete. The vulnerability is patched in plone.app.dexterity versions 3.2.3, 4.1.3, and 5.0.1, and in plone.app.contenttypes versions 3.0.12, 4.0.10, and 5.0.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
plone app.dexterity From 4.0.0 (inc) to 5.0.0 (inc)
plone app.contenttypes From 4.0.0 (inc) to 5.0.0 (inc)
plone app.dexterity 3.2.3
plone app.dexterity 4.1.3
plone app.dexterity 5.0.1
plone app.contenttypes 3.0.12
plone app.contenttypes 4.0.10
plone app.contenttypes 5.0.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Plone CMS components plone.app.dexterity and plone.app.contenttypes. An authenticated user can create content with extremely long titles, descriptions, or file names, causing the system to become unresponsive. This leads to denial of service as the affected content becomes difficult to edit or delete.

Detection Guidance

Check Plone versions for plone.app.dexterity (3.2.2, 4.0.0-4.1.2, 5.0.0) or plone.app.contenttypes (3.0.11, 4.0.0-4.0.9, 5.0.0). Inspect content with unusually long titles, descriptions, or filenames. Monitor system performance for unresponsiveness during content creation.

Impact Analysis

If exploited, this vulnerability can make your Plone CMS unresponsive, disrupting normal operations. It may also prevent you from managing or removing the malicious content, potentially leading to prolonged downtime or data management issues.

Compliance Impact

This vulnerability could indirectly impact compliance with standards like GDPR or HIPAA by causing system unavailability due to denial of service. If the Plone system becomes unresponsive, it may disrupt access to sensitive data, potentially violating availability requirements in these regulations.

Mitigation Strategies

Upgrade plone.app.dexterity to 3.2.3, 4.1.3, or 5.0.1, and plone.app.contenttypes to 3.0.12, 4.0.10, or 5.0.1. Restrict user permissions to prevent unauthorized content creation. Monitor and remove suspicious content with excessive lengths.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57576. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart