vulns.co
/
GKData.io MCP

TYPO3 · 1 min read

TYPO3: configured upload policy must reach the runtime validator

CVE-2026-15305 concerns a lifecycle mismatch between form configuration and upload enforcement. MIME validation was registered before the concrete form properties were available, so the intended validator never entered the processing pipeline. The maintainer identifies TYPO3 14.2.0–14.3.4 as affected.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

The official 14.3.5 release notes identify runtime registration of the MIME validator as the correction. Editorial lesson: a declared restriction is not evidence of enforcement. Trace configuration through construction and execution, and make absent policy enforcement a visible failure rather than an implicit success.

Before reading

  • Basic web upload handling and server-side validation
  • Content-type interpretation and processing lifecycle concepts

Context and limits

  • Exposure requires forms with file or image upload elements and configured MIME restrictions. The advisory reports acceptance of unintended MIME types, explicitly excluding PHP-file uploads; it does not establish server-side code execution or a production compromise.
  • Sébastien Convers is credited as reporter; Josua Vogel and Oliver Hader are credited with fixing the issue.
  • The official release notes date software version 14.3.5 to July 14, 2026. This happens to match advisory publication, but is a separate software-release event.
  • Editorial remediation limit: correcting validator registration does not establish that every application-specific file policy, downstream processor or storage configuration is safe.
  • Learning prerequisites and generalized design guidance are editorial. No award claim is made.

Sources and provenance

  1. TYPO3-CORE-SA-2026-020: Unrestricted File Upload in Form Framework TYPO3 · reviewed 2026-10-03
  2. TYPO3 14.3.5 Release Notes TYPO3 · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software