Impact
Wagtail versions prior to 7.0.8, 7.3.3, and 7.4.2 allow an authenticated administrator to submit specially crafted image preview filter specifications that trigger expensive rendition processing, leading to high CPU and memory consumption. This can degrade or suspend the CMS but does not affect confidentiality or integrity, and the weakness is a resource exhaustion flaw (CWE‑400).
Affected Systems
All installations of Wagtail older than versions 7.0.8, 7.3.3, or 7.4.2 that have the image preview feature enabled in the admin interface for authenticated users are vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score of less than 1% shows a very low historical exploitation probability, and the vulnerability is not listed in CISA KEV. Because only authenticated admin users can trigger the issue, ordinary visitors cannot exploit it. However, privileged users can purposely consume server resources, potentially causing service degradation in environments with weak admin controls or inadequate monitoring.
OpenCVE Enrichment