Low severity3.7NVD Advisory· Published Aug 25, 2026· Updated Aug 31, 2026
CVE-2026-72701
CVE-2026-72701
Description
Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string comparison with the === operator instead of hash_equals() for CSRF nonce validation. Attackers can measure response timing differences to recover valid nonce values byte-by-byte through multiple requests, weakening CSRF protection below its intended security margin.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
getgrav/gravPackagist | < 2.0.16 | 2.0.16 |
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
1- Grav CMS: Six Vulnerabilities Disclosed, Including Twig Sandbox Escapes and Secret LeaksVypr Intelligence · Aug 25, 2026