Home

Description

Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Extension allows HTTP DoS. This issue was remediated only on the `master` branch.

PUBLISHED Reserved 2026-04-07 | Published 2026-04-07 | Updated 2026-04-08 | Assigner wikimedia-foundation




MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L

Problem types

CWE-770 Allocation of resources without limits or throttling

Product status

Default status
unaffected

Any version before 1.43
affected

1.43
affected

1.44
affected

1.45
affected

Credits

Dreamy_Jazz finder

STran finder

References

phabricator.wikimedia.org/T414582

gerrit.wikimedia.org/.../extensions/ReportIncident/+/1226884

cve.org (CVE-2026-5762)

nvd.nist.gov (CVE-2026-5762)

Download JSON