Denial of Service in YesWiki Prior to Version 4.6.7
CVE-2026-104454

6.9MEDIUM

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104454?

Earlier versions of YesWiki, specifically prior to 4.6.7, exhibit a vulnerability within the wakka.php formatter that allows unauthenticated attackers to induce a denial of service through a specially crafted input. This input exploits an algorithmic complexity flaw in the regex handling markdown links, leading to O(n^2) processing behavior. By submitting small, crafted bodies of bracket characters to the page-edit preview endpoint, attackers can overwhelm PHP-FPM workers, effectively saturating the pool and disrupting service availability.

Affected Version(s)

yeswiki 0 < 4.6.7

yeswiki 4.6.7

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.