CVE-2026-39934
Received
Received - Intake
Infinite Loop and TOCTOU Race in Mediawiki GrowthExperiments Extension
Publication date: 2026-04-07
Last updated on: 2026-04-08
Assigner: wikimedia-foundation
Description
Description
Loop with unreachable exit condition ('infinite loop') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This issue was remediated only on the `master` branch.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| the_wikimedia_foundation | mediawiki_growthexperiments_extension | 1.45.2 |
| the_wikimedia_foundation | mediawiki_growthexperiments_extension | 1.44.4 |
| the_wikimedia_foundation | mediawiki_growthexperiments_extension | 1.43.7 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-835 | The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop. |