Security Advisory

CVE-2026-72701

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-25 01:30:23
Last updated 2026-08-27 14:54:28
Assigner VulnCheck
CVSS score 6.3
State PUBLISHED

Description

Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string comparison with the === operator instead of hash_equals() for CSRF nonce validation. Attackers can measure response timing differences to recover valid nonce values byte-by-byte through multiple requests, weakening CSRF protection below its intended security margin.