Re: MediaWiki Extensions and Skins Security Release Supplement (1.43.7/1.44.4/1.45.2)

جابر السوري via Wikitech-l <[email protected]> Thu, 9 Apr 2026 09:20:08 +0300
Newsgroups gmane.science.linguistics.wikipedia.technical,gmane.org.wikimedia.mediawiki
Message-ID <CAPmT5nD5N1ngZGbW9ozkOcKDu_M=izTCMBcQJOWshyHGzi2i3Q@mail.gmail.com>
--===============5631462051661054936==
Content-Type: multipart/alternative; boundary="0000000000000d2a54064f010249"

--0000000000000d2a54064f010249
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

=D8=A7=D9=87=D9=84=D8=A7 =D8=A8=D9=83=D9=85

=D9=81=D9=8A =D8=A7=D9=84=D8=AE=D9=85=D9=8A=D8=B3=D8=8C =D9=A9 =D8=A3=D8=A8=
=D8=B1=D9=8A=D9=84 =D9=A2=D9=A0=D9=A2=D9=A6 =D9=A1:=D9=A1=D9=A1 =D8=B5 Mary=
um Styles via Wikitech-l <
[email protected]> =D9=83=D8=AA=D8=A8:

> Greetings-
>
> With the security/maintenance release of MediaWiki 1.43.7/1.44.4/1.45.2,
> we would also like to provide this supplementary announcement of MediaWik=
i
> extensions and skins with now-public Phabricator tasks, security patches
> and backports [1]:
>
> ReportIncident
> + (T414582, CVE-2026-5762) - ReportIncident DiscussionTools integration
> causes slow requests with occasional timeouts on large talk pages
> https://gerrit.wikimedia.org/r/q/I05d7f65c57d9aa1b70cdb159c4291ac28c60b4d=
d
>
> ProofreadPage
> + (T406088, CVE-2026-39838) - ProofreadPage improperly sanitizes multilin=
e
> styles using Sanitizer::checkCSS
> https://gerrit.wikimedia.org/r/q/Idd51e18479b32b7176b43ff74ca1c49d6bdd062=
8
>
> Cargo
> + (T416271, CVE-2026-39839) - Stored XSS through URLs in Cargo's map form=
at
> https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1237957
> https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1237977
>
> Cargo
> + (T416368, CVE-2026-39840) - CSS injection in multiple Cargo display
> formats
> https://gerrit.wikimedia.org/r/c/1237966
>
> Cargo
> + (T416389, CVE-2026-39841) - Stored XSS through list fields on Cargo's
> page values and Special:CargoTables
> https://gerrit.wikimedia.org/r/c/1237973
>
> Cargo
> + (T416402, CVE-2026-39837) - Stored XSS through the dynamic table format
> in Cargo
> https://gerrit.wikimedia.org/r/c/1237979
>
> WikiLove
> +(T416502, CVE-2026-22711) - Stored XSS through system messages in WikiLo=
ve
> https://gerrit.wikimedia.org/r/q/Iab86209478a044504f5a6aea0d8c3d14f21c48b=
3
>
> CentralAuth
> +(T418122, CVE-2026-39937) - Global vanishing does not completely remove
> user email
> https://gerrit.wikimedia.org/r/q/I0b72427fa329aee85841a2cb23dec3058edce85=
e
>
> GlobalWatchlist
> +(T418179, CVE-2026-39933) - Multiple XSS vulnerabilities in
> GlobalWatchlist
> https://gerrit.wikimedia.org/r/q/I1fc7b7e1d234b0aaf9f7d782a65da1451577587=
e
>
> GrowthExperiments
> +(T418222, CVE-2026-39934) - ReassignMenteesJob runs as an infinite loop
> https://gerrit.wikimedia.org/r/c/1243874
>
> CampaignEvents
> +(T418254, CVE-2026-39935) - Stored XSS through system messages
> https://gerrit.wikimedia.org/r/c/1249320
>
> Score
> +(T419186, CVE-2026-39936) - Stored XSS due to usage of non-reserved data
> attributes
> https://gerrit.wikimedia.org/r/q/I1fb2913bc32328cbc4ecd4b4ad4a4788fb98c56=
c
>
> RenderBlocking
> +(GHSA-4h5r-8rjm-496r, CVE-2026-30977) - Stored XSS in renderblocking-css
> with Inline Assets mode
>
> https://github.com/lihaohong6/RenderBlocking/commit/096fc47dad9dca153b02c=
ba3db81f412c87fb2be
>
> The Wikimedia Security Team recommends updating these extensions and/or
> skins to the current master branch or relevant, supported release branch
> [2] as soon as possible. Some of the referenced Phabricator tasks above
> _may_ still be private. Unfortunately, when security issues are reported,
> sometimes sensitive information is exposed and since Phabricator is
> historical, we cannot make these tasks public without exposing this
> sensitive information. If you have any additional questions or concerns
> regarding this update, please feel free to contact [email protected]
> or file a security task within Phabricator [3]. CVE JSON references can b=
e
> found on Gitlab [4].
>
> [1] https://phabricator.wikimedia.org/T411394
> [2] https://www.mediawiki.org/wiki/Version_lifecycle
> [3] https://www.mediawiki.org/wiki/Reporting_security_bugs
> [4] https://gitlab.wikimedia.org/repos/security/wikimedia-cve-assignments
> _______________________________________________
> Wikitech-l mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
> https://lists.wikimedia.org/postorius/lists/wikitech-l.lists.wikimedia.or=
g/

--0000000000000d2a54064f010249
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto">=D8=A7=D9=87=D9=84=D8=A7 =D8=A8=D9=83=D9=85</div><br><div=
 class=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class=3D"gmai=
l_attr">=D9=81=D9=8A =D8=A7=D9=84=D8=AE=D9=85=D9=8A=D8=B3=D8=8C =D9=A9 =D8=
=A3=D8=A8=D8=B1=D9=8A=D9=84 =D9=A2=D9=A0=D9=A2=D9=A6 =D9=A1:=D9=A1=D9=A1 =
=D8=B5 Maryum Styles via Wikitech-l &lt;<a href=3D"mailto:wikitech-l@lists.=
wikimedia.org">[email protected]</a>&gt; =D9=83=D8=AA=D8=A8:<b=
r></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border=
-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr">Greetings-<br><br>W=
ith the security/maintenance release of MediaWiki 1.43.7/1.44.4/1.45.2, we =
would also like to provide this supplementary announcement of MediaWiki ext=
ensions and skins with now-public Phabricator tasks, security patches and b=
ackports [1]:<br><br>ReportIncident<br>+ (T414582, CVE-2026-5762) - ReportI=
ncident DiscussionTools integration causes slow requests with occasional ti=
meouts on large talk pages<br><a href=3D"https://gerrit.wikimedia.org/r/q/I=
05d7f65c57d9aa1b70cdb159c4291ac28c60b4dd" target=3D"_blank" rel=3D"noreferr=
er">https://gerrit.wikimedia.org/r/q/I05d7f65c57d9aa1b70cdb159c4291ac28c60b=
4dd</a><br><br>ProofreadPage<br>+ (T406088, CVE-2026-39838) - ProofreadPage=
 improperly sanitizes multiline styles using Sanitizer::checkCSS <br><a hre=
f=3D"https://gerrit.wikimedia.org/r/q/Idd51e18479b32b7176b43ff74ca1c49d6bdd=
0628" target=3D"_blank" rel=3D"noreferrer">https://gerrit.wikimedia.org/r/q=
/Idd51e18479b32b7176b43ff74ca1c49d6bdd0628</a><br><br>Cargo<br>+ (T416271, =
CVE-2026-39839) - Stored XSS through URLs in Cargo&#39;s map format<br><a h=
ref=3D"https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/123795=
7" target=3D"_blank" rel=3D"noreferrer">https://gerrit.wikimedia.org/r/c/me=
diawiki/extensions/Cargo/+/1237957</a><br><a href=3D"https://gerrit.wikimed=
ia.org/r/c/mediawiki/extensions/Cargo/+/1237977" target=3D"_blank" rel=3D"n=
oreferrer">https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/12=
37977</a><br><br>Cargo<br>+ (T416368, CVE-2026-39840) - CSS injection in mu=
ltiple Cargo display formats<br><a href=3D"https://gerrit.wikimedia.org/r/c=
/1237966" target=3D"_blank" rel=3D"noreferrer">https://gerrit.wikimedia.org=
/r/c/1237966</a><br><br>Cargo<br>+ (T416389, CVE-2026-39841) - Stored XSS t=
hrough list fields on Cargo&#39;s page values and Special:CargoTables<br><a=
 href=3D"https://gerrit.wikimedia.org/r/c/1237973" target=3D"_blank" rel=3D=
"noreferrer">https://gerrit.wikimedia.org/r/c/1237973</a><br><br>Cargo<br>+=
 (T416402, CVE-2026-39837) - Stored XSS through the dynamic table format in=
 Cargo<br><a href=3D"https://gerrit.wikimedia.org/r/c/1237979" target=3D"_b=
lank" rel=3D"noreferrer">https://gerrit.wikimedia.org/r/c/1237979</a><br><b=
r>WikiLove<br>+(T416502, CVE-2026-22711) - Stored XSS through system messag=
es in WikiLove<br><a href=3D"https://gerrit.wikimedia.org/r/q/Iab86209478a0=
44504f5a6aea0d8c3d14f21c48b3" target=3D"_blank" rel=3D"noreferrer">https://=
gerrit.wikimedia.org/r/q/Iab86209478a044504f5a6aea0d8c3d14f21c48b3</a><br><=
br>CentralAuth<br>+(T418122, CVE-2026-39937) - Global vanishing does not co=
mpletely remove user email<br><a href=3D"https://gerrit.wikimedia.org/r/q/I=
0b72427fa329aee85841a2cb23dec3058edce85e" target=3D"_blank" rel=3D"noreferr=
er">https://gerrit.wikimedia.org/r/q/I0b72427fa329aee85841a2cb23dec3058edce=
85e</a><br><br>GlobalWatchlist<br>+(T418179, CVE-2026-39933) - Multiple XSS=
 vulnerabilities in GlobalWatchlist<br><a href=3D"https://gerrit.wikimedia.=
org/r/q/I1fc7b7e1d234b0aaf9f7d782a65da1451577587e" target=3D"_blank" rel=3D=
"noreferrer">https://gerrit.wikimedia.org/r/q/I1fc7b7e1d234b0aaf9f7d782a65d=
a1451577587e</a><br><br>GrowthExperiments<br>+(T418222, CVE-2026-39934) - R=
eassignMenteesJob runs as an infinite loop<br><a href=3D"https://gerrit.wik=
imedia.org/r/c/1243874" target=3D"_blank" rel=3D"noreferrer">https://gerrit=
.wikimedia.org/r/c/1243874</a><br><br>CampaignEvents<br>+(T418254, CVE-2026=
-39935) - Stored XSS through system messages<br><a href=3D"https://gerrit.w=
ikimedia.org/r/c/1249320" target=3D"_blank" rel=3D"noreferrer">https://gerr=
it.wikimedia.org/r/c/1249320</a><br><br>Score<br>+(T419186, CVE-2026-39936)=
 - Stored XSS due to usage of non-reserved data attributes<br><a href=3D"ht=
tps://gerrit.wikimedia.org/r/q/I1fb2913bc32328cbc4ecd4b4ad4a4788fb98c56c" t=
arget=3D"_blank" rel=3D"noreferrer">https://gerrit.wikimedia.org/r/q/I1fb29=
13bc32328cbc4ecd4b4ad4a4788fb98c56c</a><br><br>RenderBlocking <br>+(GHSA-4h=
5r-8rjm-496r, CVE-2026-30977) - Stored XSS in renderblocking-css with Inlin=
e Assets mode<br><a href=3D"https://github.com/lihaohong6/RenderBlocking/co=
mmit/096fc47dad9dca153b02cba3db81f412c87fb2be" target=3D"_blank" rel=3D"nor=
eferrer">https://github.com/lihaohong6/RenderBlocking/commit/096fc47dad9dca=
153b02cba3db81f412c87fb2be</a><br><br>The Wikimedia Security Team recommend=
s updating these extensions and/or skins to the current master branch or re=
levant, supported release branch [2] as soon as possible. Some of the refer=
enced Phabricator tasks above _may_ still be private. Unfortunately, when s=
ecurity issues are reported, sometimes sensitive information is exposed and=
 since Phabricator is historical, we cannot make these tasks public without=
 exposing this sensitive information. If you have any additional questions =
or concerns regarding this update, please feel free to contact <a href=3D"m=
ailto:[email protected]" target=3D"_blank" rel=3D"noreferrer">security=
@wikimedia.org</a> or file a security task within Phabricator [3]. CVE JSON=
 references can be found on Gitlab [4].<br><br>[1] <a href=3D"https://phabr=
icator.wikimedia.org/T411394" target=3D"_blank" rel=3D"noreferrer">https://=
phabricator.wikimedia.org/T411394</a><br>[2] <a href=3D"https://www.mediawi=
ki.org/wiki/Version_lifecycle" target=3D"_blank" rel=3D"noreferrer">https:/=
/www.mediawiki.org/wiki/Version_lifecycle</a><br>[3] <a href=3D"https://www=
.mediawiki.org/wiki/Reporting_security_bugs" target=3D"_blank" rel=3D"noref=
errer">https://www.mediawiki.org/wiki/Reporting_security_bugs</a><br>[4] <a=
 href=3D"https://gitlab.wikimedia.org/repos/security/wikimedia-cve-assignme=
nts" target=3D"_blank" rel=3D"noreferrer">https://gitlab.wikimedia.org/repo=
s/security/wikimedia-cve-assignments</a></div>
_______________________________________________<br>
Wikitech-l mailing list -- <a href=3D"mailto:[email protected]=
" target=3D"_blank" rel=3D"noreferrer">[email protected]</a><b=
r>
To unsubscribe send an email to <a href=3D"mailto:[email protected]=
kimedia.org" target=3D"_blank" rel=3D"noreferrer">[email protected]=
kimedia.org</a><br>
<a href=3D"https://lists.wikimedia.org/postorius/lists/wikitech-l.lists.wik=
imedia.org/" rel=3D"noreferrer noreferrer" target=3D"_blank">https://lists.=
wikimedia.org/postorius/lists/wikitech-l.lists.wikimedia.org/</a></blockquo=
te></div>

--0000000000000d2a54064f010249--

--===============5631462051661054936==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Wikitech-l mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://lists.wikimedia.org/postorius/lists/wikitech-l.lists.wikimedia.org/
--===============5631462051661054936==--