CVE-2026-39934: Growth Experiments ReassignMenteesJob runs as an infinite loop
Loop with unreachable exit condition ('infinite loop') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This issue was remediated only on the master branch.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39934?
CVE-2026-39934 is considered a medium severity vulnerability due to its potential impact on system performance and reliability.
How do I fix CVE-2026-39934?
To fix CVE-2026-39934,update your MediaWiki GrowthExperiments extension to the latest version that addresses this vulnerability.
What are the risks associated with CVE-2026-39934?
The risks associated with CVE-2026-39934 include potential service downtime and degraded performance due to the infinite loop vulnerability.
Which versions of MediaWiki are affected by CVE-2026-39934?
CVE-2026-39934 affects certain versions of the MediaWiki GrowthExperiments extension, so it's crucial to check your specific version.
Is there a workaround for CVE-2026-39934 if I cannot update right away?
A temporary workaround for CVE-2026-39934 involves disabling the GrowthExperiments extension until an update can be applied.