CVE-2025-61766: Weirdgloop Mediawiki-Extensions-Bucket

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to version 1.0.0, infinite recursion can occur if a user queries a bucket using the `!=` comparator. This will result in PHP's call stack limit exceeding, and/or increased memory consumption, potentially leading to a denial of service. Version 1.0.0 contains a patch for the issue.

Affected products

  • Weirdgloop Mediawiki-Extensions-Bucket: before 1.0.0 (fixed in 1.0.0)

Published 2025-10-06. Last modified 2026-10-09.