Executive brief
A memory leak in the Scribunto extension for MediaWiki can allow an attacker to crash background processes. Scribunto is a tool used to run scripts (Lua) on wiki pages to generate dynamic content. By creating specific scripts that consume excessive memory, an attacker can cause the server's job runner to run out of memory and stop functioning, potentially delaying site updates and maintenance tasks.
Technical details
A memory leak exists in the Scribunto extension's LuaSandboxInterpreter due to improper management of engine objects stored in a WeakMap. A reference cycle prevents the PHP garbage collector from reclaiming memory used by engine objects, even when they are no longer needed. An attacker with permissions to create or edit Lua modules can trigger this leak by executing scripts that generate large amounts of data across multiple jobs. This leads to a PHP fatal error (memory exhaustion) in the runJobs.php background process, resulting in a denial-of-service for site maintenance tasks. The issue is resolved in version 1.45.2 by explicitly calling the engine destructor.
Affected products
- Wikimedia Foundation Scribunto 1.45.0 to 1.45.1
Timeline
- 2026-03-05: disclosed: Issue reported via Phabricator.
- 2026-03-19: patched: Patch developed and referenced.
- 2026-05-11: advisory: CVE-2026-34089 published.