CVE-2023-45363: Debian Linux
High severity, CVSS 7.5. EPSS: 23.8% chance of exploitation in the next 30 days.
An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It allows attackers to cause a denial of service (unbounded loop and RequestTimeoutException) when querying pages redirected to other variants with redirects and converttitles set.
Affected products
- Debian Debian Linux: version 11.0 only; version 12.0 only
- Mediawiki Mediawiki: before 1.35.12 (fixed in 1.35.12); from 1.36.0, before 1.39.5 (fixed in 1.39.5); version 1.40.0 only
Published 2023-10-09. Last modified 2026-06-17.