CVE-2026-39937

Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure.This issue affects non release branches.

Scoring

Severity
HIGH
CVSS base score
8.8
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L
EPSS probability
0.26%
CWE
CWE-212
Published
2026-04-07
Last modified
2026-04-10

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs