Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2914 articles · 109748 vulns · 38/41 feeds (7d)
← Back to list
—
CVE-2026-39934EXPLOITEDPATCHED
wikimedia foundation · growthexperiments extension

Growth Experiments ReassignMenteesJob runs as an infinite loop

Description

Loop with unreachable exit condition ('infinite loop') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This issue was remediated only on the `master` branch.

Affected Products

VendorProductVersions
wikimedia foundationgrowthexperiments extension1.45, 1.44, 1.43, 0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcemediawikicert_advisory90%

References

  • https://phabricator.wikimedia.org/T418222
  • https://gerrit.wikimedia.org/r/c/1243874

Related News (2 articles)

Tier B
BSI Advisories4h ago
[NEU] [hoch] MediaWiki Erweiterungen: Mehrere Schwachstellen ermöglichen Cross-Site Scripting
→ No new info (linked only)
Tier C
VulDB2d ago
CVE-2026-39934 | Wikimedia GrowthExperiments Extension 1.43.7/1.44.4/1.45.2 on Mediawiki infinite loop
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
1.43
CWECWE-835
PublishedApr 7, 2026
Last enriched2d agov2
Trending Score60
Source articles2
Independent2
Info Completeness7/14
Missing: cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-39840EXP
CSS injection in multiple Cargo display formats
Trending: 65
NONECVE-2026-5762EXP
ReportIncident DiscussionTools integration causes slow requests
Trending: 58
HIGHCVE-2026-39839
Stored XSS through URLs in Cargo's map format
Trending: 46
HIGHCVE-2026-39837
Stored XSS through the dynamic table format in Cargo
Trending: 46
HIGHCVE-2026-39841
Stored XSS through list fields on Cargo's page values and Special:CargoTables
Trending: 46

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 7, 2026
Discovered by ZDM
Apr 7, 2026
Updated: description, severity, activelyExploited
Apr 8, 2026
Actively Exploited
Apr 8, 2026
Patch Available
Apr 8, 2026

Version History

v2
Last enriched 2d ago
v2Tier C2d ago

Updated description with more technical detail, changed severity to HIGH, and noted that there is no exploit available.

descriptionseverityactivelyExploited
via VulDB
v12d ago

Initial creation