it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [MediaWiki-announce] MediaWiki Extensions and Skins Security Release Supplement (1.43.7/1.44.4/1.45.2)
Chronologisch Thread
- From: Scott Bassett via MediaWiki-announce <mediawiki-announce AT lists.wikimedia.org>
- To: mediawiki-announce AT lists.wikimedia.org
- Cc: Scott Bassett <sbassett AT wikimedia.org>
- Subject: [IT-SecNots] [MediaWiki-announce] MediaWiki Extensions and Skins Security Release Supplement (1.43.7/1.44.4/1.45.2)
- Date: Thu, 9 Apr 2026 10:36:30 -0500
- Arc-authentication-results: i=1; mx.google.com; arc=none
- Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=to:subject:message-id:date:from:mime-version:dkim-signature; bh=D2BZkb/sF37j2kqt/4maS+uOKorIH/sZcMnq/ejY+8M=; fh=mTzbOyoVVgzKR9C9tIIKXEAebfF3cCraLwtywicFA6Q=; b=Rg7lJ4smWwtTzrE1RL80FSo2lwFGAXw2gxmN2z24yUhelkFS9KWzeMxlIZdWxxOnzP ad6GezK262DWWcxXZZDTKmsyl+SaHF/Rzr1IEe4gG9SP4HNprWEdt0MgM+StU9tX6ql4 LRDheqBqoby7KWWwQtnsElKK4yXyit9E24Xk40SVz+btE9Ydvzz1lTp12buOoBt9mtXE PcJRzk6Xj4XyPPmUSwNUGNOEg0b2/tvTU1bO6xR6rc7QfLQ8WovcqXdCUxBsWBlsLhvq mmtBu6rTuG7NUhe5gF3ZQrBsudomKLOyL3QAjraRVvrcbYuCUW7hf0KOfAdnBCaMqSWa aHGg==; darn=lists.wikimedia.org
- Arc-seal: i=1; a=rsa-sha256; t=1775749027; cv=none; d=google.com; s=arc-20240605; b=BmJ3yv7Z7zdexYLbCnW0e6FGDbGGAn0o96xjlVWNH6blUbNJ9wBuKFUc4N85vHUbXP FxNOtLTq7RrILOst4T8I+ktKcHb5Z6UVVlqCW4ytsr+EYvFZXY3o9UR2DmCyonEz98mj 8WW4ueI1K+YIjUjjSMEVXH4PkeVLVSf4TzwHxh0X1iHjhahPPkmDDjhMF6Xqv4fLCo4c SP5EuZd74PreK0CoZxHbpCfa5K4DUe03RA0ZYngv0UetdFzWTj7PIYM8frC4uJQRdtMZ JP7C+r8Y1ehP8KYm5/FQU1pDTfNBtV9j9yKq0+r44OQeepYyMvPqayNaq/SjAjUlzcrG lZtA==
- Archived-at: <https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce AT lists.wikimedia.org/message/VXEYKT6FNA5NYFPAYU67SNTNBXLTQ4FN/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=lists.wikimedia.org header.s=wikimedia header.b=ej8jVQtV; dmarc=pass (policy=none) header.from=lists.wikimedia.org; arc=reject ("signature check failed: fail, {[1] = sig:google.com:reject}"); spf=pass (lists.piratenpartei.de: domain of mediawiki-announce-bounces AT lists.wikimedia.org designates 2620:0:861:3:208:80:154:81 as permitted sender) smtp.mailfrom=mediawiki-announce-bounces AT lists.wikimedia.org
- List-archive: <https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce AT lists.wikimedia.org/>
- List-id: MediaWiki update and security announcements list <mediawiki-announce.lists.wikimedia.org>
Greetings-
With the security/maintenance release of MediaWiki 1.43.7/1.44.4/1.45.2, we
would also like to provide this supplementary announcement of MediaWiki
extensions and skins with now-public Phabricator tasks, security patches
and backports [1]:
ReportIncident
+ (T414582, CVE-2026-5762) - ReportIncident DiscussionTools integration
causes slow requests with occasional timeouts on large talk pages
https://gerrit.wikimedia.org/r/q/I05d7f65c57d9aa1b70cdb159c4291ac28c60b4dd
ProofreadPage
+ (T406088, CVE-2026-39838) - ProofreadPage improperly sanitizes multiline
styles using Sanitizer::checkCSS
https://gerrit.wikimedia.org/r/q/Idd51e18479b32b7176b43ff74ca1c49d6bdd0628
Cargo
+ (T416271, CVE-2026-39839) - Stored XSS through URLs in Cargo's map format
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1237957
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1237977
Cargo
+ (T416368, CVE-2026-39840) - CSS injection in multiple Cargo display
formats
https://gerrit.wikimedia.org/r/c/1237966
Cargo
+ (T416389, CVE-2026-39841) - Stored XSS through list fields on Cargo's
page values and Special:CargoTables
https://gerrit.wikimedia.org/r/c/1237973
Cargo
+ (T416402, CVE-2026-39837) - Stored XSS through the dynamic table format
in Cargo
https://gerrit.wikimedia.org/r/c/1237979
WikiLove
+(T416502, CVE-2026-22711) - Stored XSS through system messages in WikiLove
https://gerrit.wikimedia.org/r/q/Iab86209478a044504f5a6aea0d8c3d14f21c48b3
CentralAuth
+(T418122, CVE-2026-39937) - Global vanishing does not completely remove
user email
https://gerrit.wikimedia.org/r/q/I0b72427fa329aee85841a2cb23dec3058edce85e
GlobalWatchlist
+(T418179, CVE-2026-39933) - Multiple XSS vulnerabilities in GlobalWatchlist
https://gerrit.wikimedia.org/r/q/I1fc7b7e1d234b0aaf9f7d782a65da1451577587e
GrowthExperiments
+(T418222, CVE-2026-39934) - ReassignMenteesJob runs as an infinite loop
https://gerrit.wikimedia.org/r/c/1243874
CampaignEvents
+(T418254, CVE-2026-39935) - Stored XSS through system messages
https://gerrit.wikimedia.org/r/c/1249320
Score
+(T419186, CVE-2026-39936) - Stored XSS due to usage of non-reserved data
attributes
https://gerrit.wikimedia.org/r/q/I1fb2913bc32328cbc4ecd4b4ad4a4788fb98c56c
RenderBlocking
+(GHSA-4h5r-8rjm-496r, CVE-2026-30977) - Stored XSS in renderblocking-css
with Inline Assets mode
https://github.com/lihaohong6/RenderBlocking/commit/096fc47dad9dca153b02cba3.
..
The Wikimedia Security Team recommends updating these extensions and/or
skins to the current master branch or relevant, supported release branch
[2] as soon as possible. Some of the referenced Phabricator tasks above
_may_ still be private. Unfortunately, when security issues are reported,
sometimes sensitive information is exposed and since Phabricator is
historical, we cannot make these tasks public without exposing this
sensitive information. If you have any additional questions or concerns
regarding this update, please feel free to contact security AT wikimedia.org
or file a security task within Phabricator [3]. CVE JSON references can be
found on Gitlab [4].
[1] https://phabricator.wikimedia.org/T411394
[2] https://www.mediawiki.org/wiki/Version_lifecycle
[3] https://www.mediawiki.org/wiki/Reporting_security_bugs
[4] https://gitlab.wikimedia.org/repos/security/wikimedia-cve-assignments
--
Scott Bassett
sbassett AT wikimedia.org
_______________________________________________
MediaWiki-announce mailing list -- mediawiki-announce AT lists.wikimedia.org
To unsubscribe send an email to mediawiki-announce-leave AT lists.wikimedia.org
- [IT-SecNots] [MediaWiki-announce] MediaWiki Extensions and Skins Security Release Supplement (1.43.7/1.44.4/1.45.2), Scott Bassett via MediaWiki-announce, 09.04.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.