Allocation of Resources Without Limits or Throttling Affecting concrete5/concrete5 package, versions >=8.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (16th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-CONCRETE5CONCRETE5-15874146
  • published2 Apr 2026
  • disclosed24 Mar 2026
  • creditWang1r

Introduced: 24 Mar 2026

CVE-2026-30662  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

There is no fixed version for concrete5/concrete5.

Overview

concrete5/concrete5 is a concrete5 open source CMS.

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in the File Manager’s bulk download functionality due to improper memory management when creating zip archives. An attacker can cause the PHP-FPM process to terminate and the web server to return a 500 error by requesting a bulk download of large files, which loads the entire content of each file into memory.

CVSS Base Scores

version 4.0
version 3.1