MEDIUM 4.3 GitHub
CVE-2026-54260
Wagtail: Denial of service via unbounded filter specs in the image preview
### Impact
An authenticated admin user can trigger expensive rendition processing with purposefully crafted filter specs resulting in potentially service degradation.
The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin.
### Patches
Patched versions have been released as Wagtail 7.0.8, 7.3.3, 7.4.2.
### Workarounds
For sites that cannot easily upgrade to a current supported version, the vulnerability can be patched by adding the following code
Affected Products
- pip/wagtail < 7.0.8
- pip/wagtail >= 7.1, < 7.3.3
- pip/wagtail >= 7.4, < 7.4.2
References
- https://github.com/advisories/GHSA-f2p5-j6fg-5cxf
- https://github.com/wagtail/wagtail/security/advisories/GHSA-f2p5-j6fg-5cxf
- https://nvd.nist.gov/vuln/detail/CVE-2026-54260
- https://github.com/pypa/advisory-database/tree/main/vulns/wagtail/PYSEC-2026-613.yaml
This medium severity vulnerability with a CVSS score of 4.3 was published on 2026-08-20 via GitHub. Affected: pip/wagtail < 7.0.8, pip/wagtail >= 7.1, < 7.3.3, pip/wagtail >= 7.4, < 7.4.2.
vulnfeed aggregates 11796 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.