Vulnerability GHSA-4595-7fjw-r3jh
Medium Risk
MEDIUM RISK
CVSS Score: 6.5
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 months ago
June 25, 2026 at 12:33 AM UTC
Tiptap contains an input validation vulnerability resulting in DoS
1.0.0 - 2.1.0
1.0.0 - 2.1.0
Summary
Tiptap contains an input validation vulnerability resulting in DoS
Details
Tiptap for PHP before version 2.1.1 contains an input validation vulnerability that allows authenticated attackers to cause a denial of service by submitting Tiptap JSON with the attrs.href field set to an array instead of a string, causing an unhandled TypeError in the Link::isAllowedUri() function when passed to preg_match(). Attackers can persist malformed JSON records that permanently crash the server-side HTML rendering pipeline for all subsequent viewers of that record until the database entry is manually repaired.
Impacted packages
Timeline
Published
3 months ago
June 25, 2026 at 12:33 AM UTC
Fixed (2.1.1)
3 months ago
June 12, 2026 at 06:19 PM UTC
Last Modified
3 hours ago
October 07, 2026 at 02:16 PM UTC