---
id: CVE-2026-57576
title: >-
  plone.app.dexterity is a content-type system for the Plone content management
  system, and plone.app.contenttypes provides Plone’s Dexterity-based content
  types
summary: >-
  plone.app.dexterity is a content-type system for the Plone content management
  system, and plone.app.contenttypes provides Plone’s Dexterity-based content
  types. Plone.app.dexterity versions through 3.2.2, 4.0.0 through 4.1.2, and
  5.0.0, …
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
vendor: plone
product: plone.app.dexterity
affected:
  - plone.app.dexterity = 5.0.0
  - 'plone.app.dexterity >= 4.0.0, < 4.1.3'
  - plone.app.dexterity < 3.2.3
  - plone.app.contenttypes = 5.0.0
  - 'plone.app.contenttypes >= 4.0.0, < 4.0.10'
  - plone.app.contenttypes < 3.0.12
published: '2026-09-22'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T18:12:04.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-57576'
references:
  - url: >-
      https://github.com/plone/plone.app.contenttypes/commit/13dc98a578341aac24a1e65fd9bc7ac8a07d168a
    label: security-advisories@github.com
  - url: >-
      https://github.com/plone/plone.app.contenttypes/commit/21bae6ebe424689eeac9a5884fc0da35f4944e63
    label: security-advisories@github.com
  - url: >-
      https://github.com/plone/plone.app.contenttypes/commit/639c0619f371df578e69ec94e5ca98e60fd6ed58
    label: security-advisories@github.com
  - url: >-
      https://github.com/plone/plone.app.contenttypes/commit/7bb03e8ec6c6bd0e645f445b0755e85a51afb158
    label: security-advisories@github.com
  - url: >-
      https://github.com/plone/plone.app.contenttypes/commit/bed1547d4f8b1fc995f2c76f30ba5f20276a8ad6
    label: security-advisories@github.com
  - url: >-
      https://github.com/plone/plone.app.contenttypes/security/advisories/GHSA-8pcw-h6w9-h46g
    label: security-advisories@github.com
  - url: >-
      https://github.com/plone/plone.app.dexterity/commit/0d317df663823445200d0569a66a95b7e4a9c50d
    label: security-advisories@github.com
  - url: >-
      https://github.com/plone/plone.app.dexterity/commit/2fdceb120ca86682a408f3a14753cfcf5126d9d9
    label: security-advisories@github.com
  - url: >-
      https://github.com/plone/plone.app.dexterity/commit/411689047f9a3521899ae6992a9b0efbd0592a8f
    label: security-advisories@github.com
  - url: >-
      https://github.com/plone/plone.app.dexterity/commit/cbcef731c0882146b9bf30688cdc639d879878fb
    label: security-advisories@github.com
  - url: >-
      https://github.com/plone/plone.app.dexterity/commit/f3596538cf7670bb8bc27b0dfa0b1da41c8b8a3a
    label: security-advisories@github.com
  - url: >-
      https://github.com/plone/plone.app.dexterity/commit/fb45bfdb18f1dfb3ed55e477947a3df9a6ee9e20
    label: security-advisories@github.com
  - url: >-
      https://github.com/plone/plone.app.dexterity/security/advisories/GHSA-5426-92w4-wvhv
    label: security-advisories@github.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-57576'
  - url: 'https://github.com/plone/plone.app.dexterity/pull/433'
  - url: 'https://github.com/plone/plone.app.dexterity/releases/tag/3.2.3'
  - url: 'https://github.com/plone/plone.app.dexterity/releases/tag/4.1.3'
  - url: 'https://github.com/plone/plone.app.dexterity/releases/tag/5.0.1'
  - url: 'https://github.com/advisories/GHSA-5426-92w4-wvhv'
  - url: 'https://github.com/plone/plone.app.dexterity'
tags:
  - nvd
  - cve.org
  - ghsa
  - pip
  - osv
epss: 0.00762
epssPercentile: 0.53394
ingestedAt: '2026-09-23T00:14:05.312Z'
aliases:
  - GHSA-5426-92w4-wvhv
ecosystem: pip
patched:
  - plone.app.dexterity 5.0.1
  - plone.app.dexterity 4.1.3
  - plone.app.dexterity 3.2.3
---

## Overview

plone.app.dexterity is a content-type system for the Plone content management system, and plone.app.contenttypes provides Plone’s Dexterity-based content types. Plone.app.dexterity versions through 3.2.2, 4.0.0 through 4.1.2, and 5.0.0, and plone.app.contenttypes versions through 3.0.11, 4.0.0 through 4.0.9, and 5.0.0 are vulnerable to denial of service because an authenticated user can create content with excessively long titles, descriptions, or uploaded-file names, causing Plone to become unresponsive and potentially making the resulting content difficult to edit or delete. The vulnerability is patched in plone.app.dexterity versions 3.2.3, 4.1.3, and 5.0.1, and in plone.app.contenttypes versions 3.0.12, 4.0.10, and 5.0.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-57576)

Affected packages:

- `plone.app.dexterity = 5.0.0`
- `plone.app.dexterity >= 4.0.0, <= 4.1.2`
- `plone.app.dexterity <= 3.2.2`

Patched in:

- `plone.app.dexterity 5.0.1`
- `plone.app.dexterity 4.1.3`
- `plone.app.dexterity 3.2.3`

Source: https://github.com/advisories/GHSA-5426-92w4-wvhv
