CVE-2026-34089: Memory leak in Scribunto causes runJobs.php to run out of memory
Published May 11, 2026
·Updated
Vulnerability in Wikimedia Foundation Scribunto.
This issue affects Scribunto: from 1.45.0 before 1.45.2.
Affected Software
2 affected components
Wikimedia Foundation Scribunto>=1.45.0<1.45.2
Wikimedia Scribunto Mediawiki>=1.45.0<1.45.2
Event History
May 11, 2026
CVE Published
via MITRE·02:46 PM
Data Sourced
via MITRE·02:46 PM
Description
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-34089?
CVE-2026-34089 has a severity rating that indicates it can cause significant memory leaks affecting performance.
2
How do I fix CVE-2026-34089?
To fix CVE-2026-34089, upgrade Wikimedia Foundation Scribunto to version 1.45.2 or later.
3
What are the consequences of CVE-2026-34089?
The consequences of CVE-2026-34089 include runJobs.php exhausting memory resources, leading to service disruptions.
4
Which versions of Scribunto are affected by CVE-2026-34089?
CVE-2026-34089 affects Scribunto versions from 1.45.0 up to, but not including, 1.45.2.
5
Is CVE-2026-34089 a critical vulnerability?
While not classified as critical, CVE-2026-34089 can lead to significant performance issues that may impact system stability.