MEDIUM 4.3 GitHub

CVE-2026-54260

Wagtail: Denial of service via unbounded filter specs in the image preview

### Impact An authenticated admin user can trigger expensive rendition processing with purposefully crafted filter specs resulting in potentially service degradation. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. ### Patches Patched versions have been released as Wagtail 7.0.8, 7.3.3, 7.4.2. ### Workarounds For sites that cannot easily upgrade to a current supported version, the vulnerability can be patched by adding the following code

Affected Products

References

Published: 2026-08-20 · Source: GitHub · Feed updated: 2026-08-20
This medium severity vulnerability with a CVSS score of 4.3 was published on 2026-08-20 via GitHub. Affected: pip/wagtail < 7.0.8, pip/wagtail >= 7.1, < 7.3.3, pip/wagtail >= 7.4, < 7.4.2.
vulnfeed aggregates 11796 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.