Resource exhaustion in wagtail - CVE-2026-54260
Published: June 16, 2026
wagtail
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the image preview view when processing crafted filter specifications. A remote user can submit a purposefully crafted filter specification to cause a denial of service.
The issue is only exploitable through the Wagtail admin interface and is not exploitable by an ordinary site visitor.