Loading
Kirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (DoS) via a malformed image upload. The application fails to properly validate the return value of the PHP getimagesize() function. When the system attempts to process this file for metadata or thumbnail generation, it triggers a fatal TypeError.
Use CWE-20, Getkirby vendor hub and Kirby product page to widen CVE-2026-29905 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-41964, CVE-2026-34587 and CVE-2026-41325 for nearby disclosures in the same product family.