CVE Vulnerabilities

CVE-2026-27127

Time-of-check Time-of-use (TOCTOU) Race Condition

Published: Feb 24, 2026 | Modified: Feb 25, 2026
CVSS 3.x
6.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation performs DNS resolution separately from the HTTP request. This Time-of-Check-Time-of-Use (TOCTOU) vulnerability enables DNS rebinding attacks, where an attacker’s DNS server returns different IP addresses for validation compared to the actual request. This is a bypass of the security fix for CVE-2025-68437 that allows access to all blocked IPs, not just IPv6 endpoints. Exploitation requires GraphQL schema permissions for editing assets in the <VolumeName> volume and creating assets in the <VolumeName> volume. These permissions may be granted to authenticated users with appropriate GraphQL schema access and/or Public Schema (if misconfigured with write permissions). Versions 4.16.19 and 5.8.23 patch the issue.

Weakness

The product checks the state of a resource before using that resource, but the resource’s state can change between the check and the use in a way that invalidates the results of the check.

Affected Software

NameVendorStart VersionEnd Version
Craft_cmsCraftcms3.5.1 (including)4.16.19 (excluding)
Craft_cmsCraftcms5.0.1 (including)5.8.23 (excluding)
Craft_cmsCraftcms3.5.0 (including)3.5.0 (including)
Craft_cmsCraftcms5.0.0 (including)5.0.0 (including)
Craft_cmsCraftcms5.0.0-rc1 (including)5.0.0-rc1 (including)

Potential Mitigations

References