
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-11175 is an Expression Language Injection vulnerability (CWE-917) in the Wikimedia Foundation's MediaWiki DiscussionTools Extension that enables Regular Expression Exponential Blowup (ReDoS). It affects DiscussionTools Extension versions 1.43 and 1.44. The vulnerability was published on January 30, 2026, and carries a CVSS v4.0 base score of 8.8 (High) (Red Hat CVE, ENISA EUVD).
The root cause is improper neutralization of special elements in expression language statements (CWE-917) within the DiscussionTools Extension's regular expression handling logic. An attacker can craft malicious input that triggers catastrophic backtracking in the regex engine — a technique known as Regular Expression Exponential Blowup (ReDoS) — causing the server-side processing to consume excessive CPU resources. The attack requires no authentication, no user interaction, and no special preconditions beyond network access to a vulnerable MediaWiki instance. Patch references are available via Wikimedia's Gerrit code review system (Phabricator T396248, Gerrit patch).
Successful exploitation can result in high confidentiality impact and low integrity impact on the vulnerable MediaWiki instance, with no direct availability impact per the CVSS v4.0 scoring. The ReDoS attack vector can degrade server performance by monopolizing CPU resources during regex evaluation, potentially affecting service responsiveness for other users. Additionally, the expression language injection component may allow unauthorized access to sensitive information and limited data modification (Red Hat CVE, ENISA EUVD).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Red Hat CVE). The vulnerability has an EPSS score of approximately 0.016% (0.000160), indicating a low probability of exploitation in the near term. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
(a+)+, ([a-zA-Z]+)*, or similar ReDoS-triggering constructs embedded within expression language syntax.Organizations should apply the patches available via Wikimedia's Gerrit code review system for the DiscussionTools Extension (Gerrit patch I563219f, Gerrit patch I126203a). A Debian security advisory (DSA-6085-1) has also been issued covering MediaWiki updates including this CVE (Debian Security Announce). As an interim workaround, administrators may consider disabling the DiscussionTools Extension entirely if patching is not immediately feasible, and should restrict network access to MediaWiki installations where possible. Monitor for suspicious regex-heavy requests targeting discussion endpoints.
A technical blog post from Infinitsec titled "CVE-2025-11175 - DiscussionTools Should Use Better Regex" provides analysis of the vulnerability (Infinitsec writeup). Debian issued a security advisory (DSA-6085-1) addressing this and related MediaWiki CVEs (Debian Security Announce). Red Hat has also tracked the vulnerability in their CVE database (Red Hat CVE). General community coverage has been limited, consistent with the low EPSS score and absence of active exploitation.
Fix availability across major Linux distributions and their releases.
bookworm
mediawiki
sid
mediawiki: 1:1.43.5+dfsg-1
trixie
mediawiki: 1:1.43.6+dfsg-1~deb13u1
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."