Produit : MediaWiki
Type : Release / Sécurité
CVE : CVE-2026-13706, CVE-2026-58518, CVE-2026-58519, CVE-2026-58520, CVE-2026-58028, CVE-2026-8857, CVE-2026-58038, CVE-2026-52854, CVE-2026-58521, CVE-2026-13707, CVE-2026-55690, CVE-2026-57440, CVE-2026-55692, CVE-2026-55691, CVE-2026-58517, CVE-2026-14358, CVE-2026-14363
Date source : 02/07/2026 20:51
Résumé :
Greetings-
With the security/maintenance release of MediaWiki 1.43.9/1.44.6/1.45.4, we
would also like to provide this supplementary announcement of MediaWiki
extensions and skins with now-public Phabricator tasks, security patches
and backports [1]:
UrlShortener
+ (T418533, CVE-2026-13706) – UrlShortener extension url validation can be
bypassed due to difference between php url parsing and WHATWG
https://gerrit.wikimedia.org/r/q/I64268dda19ea9dfa048b3e2212a682d53c2a59d6
RedirectManager
+ (T423826, CVE-2026-58518) – RedirectManager's API does not require a CSRF
token
https://gerrit.wikimedia.org/r/1275494
Cargo
+ (T424140, CVE-2026-58519) – Stored XSS through Cargo's map format
https://gerrit.wikimedia.org/r/c/1277612
UrlShortener
+ (T418431, CVE-2026-58520) – UrlShortener defaults to ineffective
validation open to third-party redirects
https://gerrit.wikimedia.org/r/1306769
Centra
Action recommandée :
Vérifier la version installée et appliquer le correctif si le produit est concerné.
Source : Voir l’annonce officielle
