CVE 6.5 MEDIUM

Bucket vulnerable to infinite recursion when querying a bucket using the != operator_CVE-2025-61766

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Description

Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to version 1.0.0, infinite recursion can occur if a user queries a bucket using the `!=` comparator. This will result in PHP's call stack limit exceeding, and/or increased memory consumption, potentially leading to a denial of service. Version 1.0.0 contains a patch for the issue.

Basic Information

ID CVE-2025-61766
Source GitHub_M
Published Oct 6, 2025 at 16:07
Modified Oct 6, 2025 at 17:16

Affected Product

Vendor weirdgloop
Product mediawiki-extensions-Bucket
Version < 1.0.0
Affected Versions weirdgloop mediawiki-extensions-Bucket < 1.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.