Unauthenticated Denial of Service in Grav via Unbounded Image Derivative Dimensions
An unauthenticated visitor can exhaust server memory and CPU by requesting an image with oversized resize dimensions in Grav, potentially taking the host down. This affects any Grav site that serves images with no account, plugin, or non-default config required. The vulnerability has a CVSS score of 8.7.