CVE-2025-61643: EventStreams publishes suppressed recent change entries that are suppressed from their creation
Published Feb 2, 2026
·Updated
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/recentchanges/RecentChangeRCFeedNotifier.Php.
This issue affects MediaWiki: from before 1.39.14, 1.43.4, 1.44.1.
Affected Software
4 affected components
Wikimedia Foundation MediaWiki>1.39.14, <1.43.4, <1.44.1
MediaWiki MediaWiki<1.39.14
MediaWiki MediaWiki>=1.43.0<1.43.4
MediaWiki MediaWiki=1.44.0
Event History
Feb 2, 2026
CVE Published
via MITRE·11:33 PM
Data Sourced
via MITRE·11:33 PM
Description
Feb 3, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-61643?
CVE-2025-61643 has been classified as a medium-severity vulnerability due to the exposure of suppressed recent change entries in MediaWiki.
2
How do I fix CVE-2025-61643?
To fix CVE-2025-61643, you should update your MediaWiki installation to version 1.43.5 or later.
3
Which versions of MediaWiki are affected by CVE-2025-61643?
CVE-2025-61643 affects MediaWiki versions prior to 1.39.14 and versions up to 1.44.1.
4
What components does CVE-2025-61643 impact?
CVE-2025-61643 impacts the includes/recentchanges/RecentChangeRCFeedNotifier.php component of MediaWiki.
5
Is there a workaround for CVE-2025-61643?
Currently, there are no known workarounds for CVE-2025-61643; updating is the recommended solution.