Re: MediaWiki Extensions and Skins Security Release Supplement (1.43.7/1.44.4/1.45.2)
جابر السوري via Wikitech-l <[email protected]> Thu, 9 Apr 2026 09:20:08 +0300
| Newsgroups | gmane.science.linguistics.wikipedia.technical,gmane.org.wikimedia.mediawiki |
|---|---|
| Message-ID | <CAPmT5nD5N1ngZGbW9ozkOcKDu_M=izTCMBcQJOWshyHGzi2i3Q@mail.gmail.com> |
--===============5631462051661054936== Content-Type: multipart/alternative; boundary="0000000000000d2a54064f010249" --0000000000000d2a54064f010249 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable =D8=A7=D9=87=D9=84=D8=A7 =D8=A8=D9=83=D9=85 =D9=81=D9=8A =D8=A7=D9=84=D8=AE=D9=85=D9=8A=D8=B3=D8=8C =D9=A9 =D8=A3=D8=A8= =D8=B1=D9=8A=D9=84 =D9=A2=D9=A0=D9=A2=D9=A6 =D9=A1:=D9=A1=D9=A1 =D8=B5 Mary= um Styles via Wikitech-l < [email protected]> =D9=83=D8=AA=D8=A8: > Greetings- > > With the security/maintenance release of MediaWiki 1.43.7/1.44.4/1.45.2, > we would also like to provide this supplementary announcement of MediaWik= i > extensions and skins with now-public Phabricator tasks, security patches > and backports [1]: > > ReportIncident > + (T414582, CVE-2026-5762) - ReportIncident DiscussionTools integration > causes slow requests with occasional timeouts on large talk pages > https://gerrit.wikimedia.org/r/q/I05d7f65c57d9aa1b70cdb159c4291ac28c60b4d= d > > ProofreadPage > + (T406088, CVE-2026-39838) - ProofreadPage improperly sanitizes multilin= e > styles using Sanitizer::checkCSS > https://gerrit.wikimedia.org/r/q/Idd51e18479b32b7176b43ff74ca1c49d6bdd062= 8 > > Cargo > + (T416271, CVE-2026-39839) - Stored XSS through URLs in Cargo's map form= at > https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1237957 > https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1237977 > > Cargo > + (T416368, CVE-2026-39840) - CSS injection in multiple Cargo display > formats > https://gerrit.wikimedia.org/r/c/1237966 > > Cargo > + (T416389, CVE-2026-39841) - Stored XSS through list fields on Cargo's > page values and Special:CargoTables > https://gerrit.wikimedia.org/r/c/1237973 > > Cargo > + (T416402, CVE-2026-39837) - Stored XSS through the dynamic table format > in Cargo > https://gerrit.wikimedia.org/r/c/1237979 > > WikiLove > +(T416502, CVE-2026-22711) - Stored XSS through system messages in WikiLo= ve > https://gerrit.wikimedia.org/r/q/Iab86209478a044504f5a6aea0d8c3d14f21c48b= 3 > > CentralAuth > +(T418122, CVE-2026-39937) - Global vanishing does not completely remove > user email > https://gerrit.wikimedia.org/r/q/I0b72427fa329aee85841a2cb23dec3058edce85= e > > GlobalWatchlist > +(T418179, CVE-2026-39933) - Multiple XSS vulnerabilities in > GlobalWatchlist > https://gerrit.wikimedia.org/r/q/I1fc7b7e1d234b0aaf9f7d782a65da1451577587= e > > GrowthExperiments > +(T418222, CVE-2026-39934) - ReassignMenteesJob runs as an infinite loop > https://gerrit.wikimedia.org/r/c/1243874 > > CampaignEvents > +(T418254, CVE-2026-39935) - Stored XSS through system messages > https://gerrit.wikimedia.org/r/c/1249320 > > Score > +(T419186, CVE-2026-39936) - Stored XSS due to usage of non-reserved data > attributes > https://gerrit.wikimedia.org/r/q/I1fb2913bc32328cbc4ecd4b4ad4a4788fb98c56= c > > RenderBlocking > +(GHSA-4h5r-8rjm-496r, CVE-2026-30977) - Stored XSS in renderblocking-css > with Inline Assets mode > > https://github.com/lihaohong6/RenderBlocking/commit/096fc47dad9dca153b02c= ba3db81f412c87fb2be > > The Wikimedia Security Team recommends updating these extensions and/or > skins to the current master branch or relevant, supported release branch > [2] as soon as possible. Some of the referenced Phabricator tasks above > _may_ still be private. Unfortunately, when security issues are reported, > sometimes sensitive information is exposed and since Phabricator is > historical, we cannot make these tasks public without exposing this > sensitive information. If you have any additional questions or concerns > regarding this update, please feel free to contact [email protected] > or file a security task within Phabricator [3]. CVE JSON references can b= e > found on Gitlab [4]. > > [1] https://phabricator.wikimedia.org/T411394 > [2] https://www.mediawiki.org/wiki/Version_lifecycle > [3] https://www.mediawiki.org/wiki/Reporting_security_bugs > [4] https://gitlab.wikimedia.org/repos/security/wikimedia-cve-assignments > _______________________________________________ > Wikitech-l mailing list -- [email protected] > To unsubscribe send an email to [email protected] > https://lists.wikimedia.org/postorius/lists/wikitech-l.lists.wikimedia.or= g/ --0000000000000d2a54064f010249 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"auto">=D8=A7=D9=87=D9=84=D8=A7 =D8=A8=D9=83=D9=85</div><br><div= class=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class=3D"gmai= l_attr">=D9=81=D9=8A =D8=A7=D9=84=D8=AE=D9=85=D9=8A=D8=B3=D8=8C =D9=A9 =D8= =A3=D8=A8=D8=B1=D9=8A=D9=84 =D9=A2=D9=A0=D9=A2=D9=A6 =D9=A1:=D9=A1=D9=A1 = =D8=B5 Maryum Styles via Wikitech-l <<a href=3D"mailto:wikitech-l@lists.= wikimedia.org">[email protected]</a>> =D9=83=D8=AA=D8=A8:<b= r></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border= -left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr">Greetings-<br><br>W= ith the security/maintenance release of MediaWiki 1.43.7/1.44.4/1.45.2, we = would also like to provide this supplementary announcement of MediaWiki ext= ensions and skins with now-public Phabricator tasks, security patches and b= ackports [1]:<br><br>ReportIncident<br>+ (T414582, CVE-2026-5762) - ReportI= ncident DiscussionTools integration causes slow requests with occasional ti= meouts on large talk pages<br><a href=3D"https://gerrit.wikimedia.org/r/q/I= 05d7f65c57d9aa1b70cdb159c4291ac28c60b4dd" target=3D"_blank" rel=3D"noreferr= er">https://gerrit.wikimedia.org/r/q/I05d7f65c57d9aa1b70cdb159c4291ac28c60b= 4dd</a><br><br>ProofreadPage<br>+ (T406088, CVE-2026-39838) - ProofreadPage= improperly sanitizes multiline styles using Sanitizer::checkCSS <br><a hre= f=3D"https://gerrit.wikimedia.org/r/q/Idd51e18479b32b7176b43ff74ca1c49d6bdd= 0628" target=3D"_blank" rel=3D"noreferrer">https://gerrit.wikimedia.org/r/q= /Idd51e18479b32b7176b43ff74ca1c49d6bdd0628</a><br><br>Cargo<br>+ (T416271, = CVE-2026-39839) - Stored XSS through URLs in Cargo's map format<br><a h= ref=3D"https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/123795= 7" target=3D"_blank" rel=3D"noreferrer">https://gerrit.wikimedia.org/r/c/me= diawiki/extensions/Cargo/+/1237957</a><br><a href=3D"https://gerrit.wikimed= ia.org/r/c/mediawiki/extensions/Cargo/+/1237977" target=3D"_blank" rel=3D"n= oreferrer">https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/12= 37977</a><br><br>Cargo<br>+ (T416368, CVE-2026-39840) - CSS injection in mu= ltiple Cargo display formats<br><a href=3D"https://gerrit.wikimedia.org/r/c= /1237966" target=3D"_blank" rel=3D"noreferrer">https://gerrit.wikimedia.org= /r/c/1237966</a><br><br>Cargo<br>+ (T416389, CVE-2026-39841) - Stored XSS t= hrough list fields on Cargo's page values and Special:CargoTables<br><a= href=3D"https://gerrit.wikimedia.org/r/c/1237973" target=3D"_blank" rel=3D= "noreferrer">https://gerrit.wikimedia.org/r/c/1237973</a><br><br>Cargo<br>+= (T416402, CVE-2026-39837) - Stored XSS through the dynamic table format in= Cargo<br><a href=3D"https://gerrit.wikimedia.org/r/c/1237979" target=3D"_b= lank" rel=3D"noreferrer">https://gerrit.wikimedia.org/r/c/1237979</a><br><b= r>WikiLove<br>+(T416502, CVE-2026-22711) - Stored XSS through system messag= es in WikiLove<br><a href=3D"https://gerrit.wikimedia.org/r/q/Iab86209478a0= 44504f5a6aea0d8c3d14f21c48b3" target=3D"_blank" rel=3D"noreferrer">https://= gerrit.wikimedia.org/r/q/Iab86209478a044504f5a6aea0d8c3d14f21c48b3</a><br><= br>CentralAuth<br>+(T418122, CVE-2026-39937) - Global vanishing does not co= mpletely remove user email<br><a href=3D"https://gerrit.wikimedia.org/r/q/I= 0b72427fa329aee85841a2cb23dec3058edce85e" target=3D"_blank" rel=3D"noreferr= er">https://gerrit.wikimedia.org/r/q/I0b72427fa329aee85841a2cb23dec3058edce= 85e</a><br><br>GlobalWatchlist<br>+(T418179, CVE-2026-39933) - Multiple XSS= vulnerabilities in GlobalWatchlist<br><a href=3D"https://gerrit.wikimedia.= org/r/q/I1fc7b7e1d234b0aaf9f7d782a65da1451577587e" target=3D"_blank" rel=3D= "noreferrer">https://gerrit.wikimedia.org/r/q/I1fc7b7e1d234b0aaf9f7d782a65d= a1451577587e</a><br><br>GrowthExperiments<br>+(T418222, CVE-2026-39934) - R= eassignMenteesJob runs as an infinite loop<br><a href=3D"https://gerrit.wik= imedia.org/r/c/1243874" target=3D"_blank" rel=3D"noreferrer">https://gerrit= .wikimedia.org/r/c/1243874</a><br><br>CampaignEvents<br>+(T418254, CVE-2026= -39935) - Stored XSS through system messages<br><a href=3D"https://gerrit.w= ikimedia.org/r/c/1249320" target=3D"_blank" rel=3D"noreferrer">https://gerr= it.wikimedia.org/r/c/1249320</a><br><br>Score<br>+(T419186, CVE-2026-39936)= - Stored XSS due to usage of non-reserved data attributes<br><a href=3D"ht= tps://gerrit.wikimedia.org/r/q/I1fb2913bc32328cbc4ecd4b4ad4a4788fb98c56c" t= arget=3D"_blank" rel=3D"noreferrer">https://gerrit.wikimedia.org/r/q/I1fb29= 13bc32328cbc4ecd4b4ad4a4788fb98c56c</a><br><br>RenderBlocking <br>+(GHSA-4h= 5r-8rjm-496r, CVE-2026-30977) - Stored XSS in renderblocking-css with Inlin= e Assets mode<br><a href=3D"https://github.com/lihaohong6/RenderBlocking/co= mmit/096fc47dad9dca153b02cba3db81f412c87fb2be" target=3D"_blank" rel=3D"nor= eferrer">https://github.com/lihaohong6/RenderBlocking/commit/096fc47dad9dca= 153b02cba3db81f412c87fb2be</a><br><br>The Wikimedia Security Team recommend= s updating these extensions and/or skins to the current master branch or re= levant, supported release branch [2] as soon as possible. Some of the refer= enced Phabricator tasks above _may_ still be private. Unfortunately, when s= ecurity issues are reported, sometimes sensitive information is exposed and= since Phabricator is historical, we cannot make these tasks public without= exposing this sensitive information. If you have any additional questions = or concerns regarding this update, please feel free to contact <a href=3D"m= ailto:[email protected]" target=3D"_blank" rel=3D"noreferrer">security= @wikimedia.org</a> or file a security task within Phabricator [3]. CVE JSON= references can be found on Gitlab [4].<br><br>[1] <a href=3D"https://phabr= icator.wikimedia.org/T411394" target=3D"_blank" rel=3D"noreferrer">https://= phabricator.wikimedia.org/T411394</a><br>[2] <a href=3D"https://www.mediawi= ki.org/wiki/Version_lifecycle" target=3D"_blank" rel=3D"noreferrer">https:/= /www.mediawiki.org/wiki/Version_lifecycle</a><br>[3] <a href=3D"https://www= .mediawiki.org/wiki/Reporting_security_bugs" target=3D"_blank" rel=3D"noref= errer">https://www.mediawiki.org/wiki/Reporting_security_bugs</a><br>[4] <a= href=3D"https://gitlab.wikimedia.org/repos/security/wikimedia-cve-assignme= nts" target=3D"_blank" rel=3D"noreferrer">https://gitlab.wikimedia.org/repo= s/security/wikimedia-cve-assignments</a></div> _______________________________________________<br> Wikitech-l mailing list -- <a href=3D"mailto:[email protected]= " target=3D"_blank" rel=3D"noreferrer">[email protected]</a><b= r> To unsubscribe send an email to <a href=3D"mailto:[email protected]= kimedia.org" target=3D"_blank" rel=3D"noreferrer">[email protected]= kimedia.org</a><br> <a href=3D"https://lists.wikimedia.org/postorius/lists/wikitech-l.lists.wik= imedia.org/" rel=3D"noreferrer noreferrer" target=3D"_blank">https://lists.= wikimedia.org/postorius/lists/wikitech-l.lists.wikimedia.org/</a></blockquo= te></div> --0000000000000d2a54064f010249-- --===============5631462051661054936== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Wikitech-l mailing list -- [email protected] To unsubscribe send an email to [email protected] https://lists.wikimedia.org/postorius/lists/wikitech-l.lists.wikimedia.org/ --===============5631462051661054936==--