Denial of Service in YesWiki Prior to Version 4.6.7
CVE-2026-104454
6.9MEDIUM
What is CVE-2026-104454?
Earlier versions of YesWiki, specifically prior to 4.6.7, exhibit a vulnerability within the wakka.php formatter that allows unauthenticated attackers to induce a denial of service through a specially crafted input. This input exploits an algorithmic complexity flaw in the regex handling markdown links, leading to O(n^2) processing behavior. By submitting small, crafted bodies of bracket characters to the page-edit preview endpoint, attackers can overwhelm PHP-FPM workers, effectively saturating the pool and disrupting service availability.
Affected Version(s)
yeswiki 0 < 4.6.7
yeswiki 4.6.7
