CVE-2025-61641: API list=allpages with maxsize is making really slow queries
Published Feb 2, 2026
·Updated
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/api/ApiQueryAllPages.Php.
This issue affects MediaWiki: from before 1.39.14, 1.43.4, 1.44.1.
Affected Software
4 affected components
Wikimedia Foundation MediaWiki<1.39.14
MediaWiki MediaWiki<1.39.14
MediaWiki MediaWiki>=1.43.0<1.43.4
MediaWiki MediaWiki=1.44.0
Event History
Feb 2, 2026
CVE Published
via MITRE·11:39 PM
Data Sourced
via MITRE·11:39 PM
Description
Feb 3, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-61641?
CVE-2025-61641 is classified as a vulnerability that causes slow queries in Wikimedia Foundation MediaWiki.
2
How do I fix CVE-2025-61641?
To fix CVE-2025-61641, upgrade to MediaWiki versions 1.39.14, 1.43.4, or 1.44.1 or later.
3
Which versions of MediaWiki are affected by CVE-2025-61641?
CVE-2025-61641 affects MediaWiki versions prior to 1.39.14, 1.43.4, and 1.44.1.
4
What component of MediaWiki does CVE-2025-61641 impact?
CVE-2025-61641 impacts the API functionality, specifically the api/ApiQueryAllPages.php file.
5
How can I identify if my MediaWiki installation is vulnerable to CVE-2025-61641?
You can identify if you are vulnerable to CVE-2025-61641 by checking your MediaWiki version against the affected versions mentioned.