Resource Overallocation Issue in Wikimedia Foundation's Mediawiki - CirrusSearch Extension
CVE-2025-62666

6.9MEDIUM

What is CVE-2025-62666?

The Wikimedia Foundation's Mediawiki - CirrusSearch Extension contains a resource allocation vulnerability that allows for HTTP Denial of Service (DoS) attacks. This issue arises from the allocation of resources without sufficient limits or throttling mechanisms, potentially leading to service disruptions. Affected users utilizing versions of the extension prior to 1.43 may experience performance degradation or complete outages under certain conditions.

Affected Version(s)

Mediawiki - CirrusSearch Extension master < 1.43

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dreamy_jazz
dcausse
.
CVE-2025-62666 : Resource Overallocation Issue in Wikimedia Foundation's Mediawiki - CirrusSearch Extension