CVE-2026-100242: DataTransfer depends on phpspreadsheet version vulnerable to CVE-2026-59933 (XLS/OLE memory exhaustion)
Dependency on Vulnerable Third-Party Component and Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - DataTransfer Extension allows Excessive Allocation.
This issue affects Mediawiki - DataTransfer Extension: from 1.46.0 before 1.47.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wikimedia MediaWiki DataTransfer Extensionto a version that resolves this vulnerability.Fixed in 1.47.0
Event History
Frequently Asked Questions
Which deployments are affected?
MediaWiki installations using the DataTransfer Extension are affected from version 1.46.0 up to, but not including, 1.47.0.
What is the practical impact of exploitation?
The issue can cause excessive memory allocation while processing XLS/OLE content, which can exhaust available memory and disrupt the affected service.
What should administrators do?
Upgrade the MediaWiki DataTransfer Extension to version 1.47.0 or later.