CVE-2026-65650

Summary

Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.

Affected Software

VendorProductVersion RangeStatus
ElggElgg0 < 6.3.5affected
ElggElgg7.0.0-rc.1 < 7.0.0affected

Weaknesses

  • CWE-770: CWE-770 Allocation of Resources Without Limits or Throttling

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References