---
id: CVE-2026-47110
aliases:
  - GHSA-4595-7fjw-r3jh
title: Tiptap contains an input validation vulnerability resulting in DoS
summary: Tiptap contains an input validation vulnerability resulting in DoS
severity: high
cvss: 6.5
cwe:
  - CWE-241
vendor: ueberdosis
product: ueberdosis/tiptap-php
ecosystem: composer
affected:
  - ueberdosis/tiptap-php < 2.1.1
patched:
  - ueberdosis/tiptap-php 2.1.1
published: '2026-06-25'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T14:01:59Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-4595-7fjw-r3jh'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-47110'
  - url: 'https://github.com/ueberdosis/tiptap-php/pull/94'
  - url: >-
      https://github.com/ueberdosis/tiptap-php/commit/74bfb7be1c8c6102b240f3879b7f984a6ab87b97
  - url: 'https://github.com/ueberdosis/tiptap-php/releases/tag/2.1.1'
  - url: >-
      https://www.vulncheck.com/advisories/tiptap-for-php-dos-via-malformed-href-attribute
  - url: 'https://github.com/advisories/GHSA-4595-7fjw-r3jh'
tags:
  - ghsa
  - composer
epss: 0.00548
epssPercentile: 0.44056
ingestedAt: '2026-10-07T14:33:21.959Z'
---

## Overview

Tiptap for PHP before version 2.1.1 contains an input validation vulnerability that allows authenticated attackers to cause a denial of service by submitting Tiptap JSON with the attrs.href field set to an array instead of a string, causing an unhandled TypeError in the Link::isAllowedUri() function when passed to preg_match(). Attackers can persist malformed JSON records that permanently crash the server-side HTML rendering pipeline for all subsequent viewers of that record until the database entry is manually repaired.

## Affected packages

- `ueberdosis/tiptap-php < 2.1.1`

## Remediation

Upgrade to a patched release:

- `ueberdosis/tiptap-php 2.1.1`
