PT-2026-40943 · Givanz · Vvveb

Basant Kumar

+1

·

Published

2026-05-14

·

Updated

2026-05-14

·

CVE-2026-41935

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
Vvveb before 1.0.8.3 contains an uncontrolled recursion vulnerability in the admin controller dispatch cycle where Base::init() repeatedly invokes permission() on error handlers, causing infinite recursion until PHP memory limits are exhausted. Attackers can send sustained requests to forbidden admin URLs from a low-privilege account to exhaust PHP memory on all workers and cause denial of service to legitimate traffic.

Fix

Uncontrolled Recursion

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2026-41935

Affected Products

Vvveb