CRITICAL
9.1 CVE-2026-55248 Published 28 Aug 2026
Plone RSS Portlet Denial of Service
Worried this affects one of your servers?
Plone's plone.app.portlets component, which provides portlets and a user interface for Plone, is affected by a denial of service vulnerability.
Prior to versions 5.0.8, 6.0.4, and 7.0.2, an authenticated user could set an RSS portlet's feed URL to a large response, causing excessive data to be downloaded and retained in memory, leading to a denial of service.
The same URL handling also accepts internal hosts, IP addresses, single-word domains, and explicit ports, allowing server-side requests to probe internal network services. Additionally, a malicious feed item can supply a JavaScript URL that can execute script when used by a victim.
Reference: CVE-2026-55248 on NVD
← Back to Security News