Junglewise Threat Intelligence

CVE-2026-13706: Wikimedia Foundation UrlShortener improper input validation in UrlShortenerUtils

CVE-2026-13706 · Severity: info · CVSS 0 · Published 2026-07-01

Vendors: Wikimedia Foundation.

Executive brief

A vulnerability exists in the Wikimedia Foundation UrlShortener, a tool used to create shortened web links for MediaWiki-based sites. While the technical impact is rated as low, improper handling of input could potentially lead to unexpected behavior when processing URLs. This issue primarily affects the internal utility functions used to generate or validate short links.

Technical details

An improper input validation vulnerability (CWE-20) exists in the UrlShortener extension for MediaWiki, specifically within the 'includes/UrlShortenerUtils.php' file. The flaw allows for improper processing of input data when handled by the utility functions of the extension. According to the vendor's CVSS 4.0 assessment, the vulnerability requires low privileges (PR:L) and is network exploitable, but it currently carries a base score of 0.0 as it does not directly result in loss of confidentiality, integrity, or availability. The issue affects multiple versions up to 1.46.0.

Affected products

  • Wikimedia Foundation UrlShortener <= 1.46.0, 1.45.4, 1.44.6, 1.43.9

Timeline

  • 2026-07-01: advisory: NVD publication date

References

Related threats