CVE-2025-61634: HTML rest endpoint needs PoolCounter and proper parser cache check
Published Feb 2, 2026
·Updated
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Rest/Handler/PageHTMLHandler.Php.
This issue affects MediaWiki: from before 1.39.14, 1.43.4, 1.44.1.
Affected Software
4 affected components
Wikimedia Foundation MediaWiki>1.39.14
MediaWiki MediaWiki<1.39.14
MediaWiki MediaWiki>=1.39.15<1.43.4
MediaWiki MediaWiki>=1.43.5<1.44.1
Event History
Feb 2, 2026
CVE Published
via MITRE·11:28 PM
Data Sourced
via MITRE·11:28 PM
Description
Feb 3, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-61634?
CVE-2025-61634 has a moderate severity level, which may lead to issues in handling requests to HTML endpoints.
2
How do I fix CVE-2025-61634?
To fix CVE-2025-61634, upgrade MediaWiki to version 1.39.14 or later, or versions 1.43.4 and 1.44.1.
3
What versions of MediaWiki are affected by CVE-2025-61634?
CVE-2025-61634 affects MediaWiki versions before 1.39.14, 1.43.4, and 1.44.1.
4
What files are related to CVE-2025-61634?
CVE-2025-61634 is related to the program file includes/Rest/Handler/PageHTMLHandler.php.
5
What type of vulnerability is CVE-2025-61634?
CVE-2025-61634 is a vulnerability in HTML REST endpoint processing in MediaWiki.