CRITICAL 9.1 CVE-2026-55248 Published 28 Aug 2026

Plone RSS Portlet Denial of Service

Worried this affects one of your servers?

Plone's plone.app.portlets component, which provides portlets and a user interface for Plone, is affected by a denial of service vulnerability.

Prior to versions 5.0.8, 6.0.4, and 7.0.2, an authenticated user could set an RSS portlet's feed URL to a large response, causing excessive data to be downloaded and retained in memory, leading to a denial of service.

The same URL handling also accepts internal hosts, IP addresses, single-word domains, and explicit ports, allowing server-side requests to probe internal network services. Additionally, a malicious feed item can supply a JavaScript URL that can execute script when used by a victim.

Reference: CVE-2026-55248 on NVD

← Back to Security News