CVE-2026-104454: YesWiki before 4.6.7 ReDoS via wakka.php Edit-Preview Endpoint
YesWiki before 4.6.7 contains an algorithmic-complexity denial of service in the wakka.php formatter due to an O(n^2) markdown-link regex. Unauthenticated attackers can submit a small crafted body of bracket characters to the page-edit preview endpoint to pin PHP-FPM workers and saturate the pool.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
YesWiki versions before 4.6.7 are affected. The vulnerable functionality is the page-edit preview endpoint, where submitted content is processed by the wakka.php formatter.
Does exploitation require an account or user interaction?
No. An unauthenticated attacker can submit a crafted request to the preview endpoint, and no user interaction is required.
What is the practical impact of a successful attack?
A small body containing crafted bracket characters can trigger quadratic regex processing. This can pin PHP-FPM workers and saturate the PHP-FPM pool, causing a denial of service.