CVE-2025-67476: Importing leaks IP address of importer via EventStreams
Published Feb 3, 2026
·Updated
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/ImportableOldRevisionImporter.Php.
This issue affects MediaWiki: from before 1.44.3, 1.45.1.
Affected Software
3 affected components
Wikimedia Foundation MediaWiki>1.44.3
MediaWiki MediaWiki>=1.44.0<1.44.3
MediaWiki MediaWiki=1.45.0
Event History
Feb 3, 2026
CVE Published
via MITRE·01:18 AM
Data Sourced
via MITRE·01:18 AM
Description
Data Sourced
via NVD·02:16 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-67476?
CVE-2025-67476 is considered a medium severity vulnerability due to the potential exposure of sensitive user information.
2
How do I fix CVE-2025-67476?
To fix CVE-2025-67476, upgrade to MediaWiki version 1.44.3 or 1.45.1 or later.
3
Which versions of MediaWiki are affected by CVE-2025-67476?
CVE-2025-67476 affects MediaWiki versions before 1.44.3 and 1.45.1.
4
What type of vulnerability is CVE-2025-67476?
CVE-2025-67476 is an information disclosure vulnerability that leaks the IP address of the importer.
5
What component of MediaWiki is involved in CVE-2025-67476?
The vulnerable component in MediaWiki associated with CVE-2025-67476 is includes/Import/ImportableOldRevisionImporter.php.