CVE-2026-39934 Details
Description
Loop with unreachable exit condition ('infinite loop') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This issue was remediated only on the `master` branch.
A vulnerability in the Wikimedia Foundation's MediaWiki GrowthExperiments Extension, specifically in versions 1.45.2, 1.44.4, and 1.43.7, allows for an infinite loop condition in the ReassignMenteesJob process. This issue arises from a race condition related to the handling of hidden mentees, causing the job to run repeatedly without completing its task.
Users can update to MediaWiki GrowthExperiments Extension versions 1.46.0-wmf.16 or 1.46.0-wmf.17, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gerrit.wikimedia.org/r/c/1243874 | wikimedia-foundation | |
| https://phabricator.wikimedia.org/T418222 | wikimedia-foundation |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-835 | Loop with Unreachable Exit Condition ('Infinite Loop') | wikimedia-foundation |
Affected Products
No affected product data is available for this CVE.
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | wikimedia-foundation |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 8, 2026 | CVE Modified | wikimedia-foundation |
| Apr 7, 2026 | New CVE Received | wikimedia-foundation |