CVE-2026-55248
Published:August 28, 2026
Updated:September 24, 2026
plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior to 5.0.8, 6.0.4, and 7.0.2, a member who can add an RSS portlet can set its feed URL to a very large response, causing src/plone/app/portlets/portlets/rss.py to download and retain excessive data in memory and deny service. The same RSS URL handling accepts internal hosts, IP addresses, single-word domains, and explicit ports, allowing server-side requests that can probe internal network services and open ports. A malicious feed item can also supply a JavaScript URL that is retained as the item link and can execute script when used by a victim. The affected logic includes _rss_feed_url_validator, _normal_url_validator, RSSFeed._retrieveFeed, RSSFeed._buildItemDict, and the FEED_DATA in-memory cache. This issue is fixed in versions 5.0.8, 6.0.4, and 7.0.2.
Affected Packages
https://github.com/plone/plone.app.portlets.git (GITHUB):
Affected version(s) >=1.0 <7.0.2Fix Suggestion:
Update to version 7.0.2plone.app.portlets (PYTHON):
Affected version(s) >=6.0.0 <6.0.4Fix Suggestion:
Update to version 6.0.4plone.app.portlets (PYTHON):
Affected version(s) >=1.0a2 <5.0.8Fix Suggestion:
Update to version 5.0.8plone.app.portlets (PYTHON):
Affected version(s) >=7.0.0 <7.0.2Fix Suggestion:
Update to version 7.0.2Related Resources (8)
Do you need more information?
Contact UsCVSS v4
Base Score:
8.5
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
Vulnerable System Confidentiality
LOW
Vulnerable System Integrity
LOW
Vulnerable System Availability
HIGH
Subsequent System Confidentiality
LOW
Subsequent System Integrity
LOW
Subsequent System Availability
HIGH
CVSS v3
Base Score:
9.1
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
HIGH
Weakness Type (CWE)
Uncontrolled Resource Consumption
EPSS
Base Score:
0.32