CVE-2026-105686
Deferred Deferred - Pending Action

Memory Corruption in Penpot Design Platform

Vulnerability report for CVE-2026-105686, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the chunked media upload RPC validates that a chunk index is in range but neither rejects an already stored index nor replaces its previous object. An authenticated user can repeatedly upload the same valid index, causing each successful request to allocate another temporary object and increasing stored bytes beyond the upload session's declared logical size. Assembly detects the inconsistent chunk count only after allocation. This issue is fixed in version 2.18.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
penpot penpot < 2.18.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105686 is a storage amplification vulnerability in Penpot affecting versions up to 2.17.2. It occurs during chunked media uploads where the system validates chunk indices but fails to prevent duplicate submissions. An authenticated user can repeatedly upload the same valid chunk index, creating multiple temporary objects despite the session declaring only one chunk. This leads to unnecessary storage consumption as each submission allocates new objects.

Detection Guidance

To detect this vulnerability, monitor for repeated chunk index submissions in Penpot's upload sessions. Check server logs for multiple temporary objects created from the same session/index pair. Look for storage usage spikes in temporary directories or databases used by Penpot. Use network monitoring to identify clients repeatedly sending the same chunk index.

Impact Analysis

This vulnerability allows low-privilege users to consume shared temporary storage by repeatedly submitting the same chunk index. Each submission creates a new temporary object, increasing storage usage beyond the declared session size. In a test case, four requests created four objects totaling four times the declared chunk size. This could lead to resource exhaustion and potential denial of service for other users sharing the same storage.

Compliance Impact

This vulnerability primarily causes uncontrolled storage consumption by allowing authenticated users to repeatedly upload the same chunk index, creating multiple temporary objects. While it does not directly expose or leak data, it could indirectly impact compliance by consuming excessive storage resources in shared environments, potentially violating resource allocation policies in GDPR (data minimization) or HIPAA (resource management). However, no direct evidence links this issue to data breaches or unauthorized access.

Mitigation Strategies

Upgrade Penpot to version 2.18.0 or later to apply the fix. If upgrading is not immediately possible, enforce uniqueness for upload-session/index pairs and implement rate limiting on upload sessions. Set a 30 MiB cap on chunk sizes via the :upload-max-chunk-size configuration. Monitor storage usage and remove any duplicate temporary objects created by this issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105686. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart