CVE-2025-61639
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-61639 is an information disclosure vulnerability (CWE-200/CWE-213) in Wikimedia Foundation MediaWiki that exposes sensitive information to unauthorized actors through the logging and recent changes subsystems. It affects MediaWiki versions before 1.39.14, before 1.43.4 (in the 1.43.x branch), and before 1.44.1 (in the 1.44.x branch). The vulnerability was published on February 3, 2026, and has a CVSS v3.1 base score of 4.8 (Medium) and a CVSS v4.0 base score of 1.7 (Low) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The vulnerability is rooted in improper information exposure (CWE-200) and exposure of sensitive information due to incompatible policies (CWE-213) within three specific MediaWiki source files: includes/logging/ManualLogEntry.php, includes/recentchanges/RecentChangeFactory.php, and includes/recentchanges/RecentChangeStore.php. These components handle the generation and storage of log entries and recent change records, and under certain conditions they may surface sensitive data — such as suppressed or blocked IP addresses — to users who should not have access to it (e.g., via Special:BlockList, Recent Changes, or related pages). The attack vector is network-based with low attack complexity, though exploitation may require specific preconditions (attack requirements are noted as "present" in the CVSS v4.0 assessment) (Red Hat Advisory, Red Hat Bugzilla).

Impact

Successful exploitation allows unauthorized actors to view sensitive information that should be restricted, such as suppressed blocked IP addresses visible in Special:BlockList, Recent Changes, and other MediaWiki interfaces. The confidentiality impact is limited in scope — no integrity or availability impact has been identified — but the exposure of suppressed user or IP data could undermine privacy protections for wiki editors and administrators who rely on MediaWiki's suppression features (Red Hat Advisory, Red Hat Bugzilla).

Mitigation and workarounds

Wikimedia Foundation has released patched versions of MediaWiki addressing this vulnerability. Administrators should upgrade to MediaWiki 1.39.14 (for the 1.39.x LTS branch), 1.43.4 (for the 1.43.x branch), or 1.44.1 (for the 1.44.x branch) or any later release. As an interim measure, administrators should audit access controls on logging and recent changes pages and review suppression configurations. Debian LTS users can apply the fix via the DLA-4355-1 security update, and Mageia users via MGASA-2025-0260 (Red Hat Bugzilla, Debian LTS Announce, Debian Security Announce).

Community reactions

The vulnerability received routine coverage from Linux distribution security teams, with Debian issuing DLA-4355-1 and DSA-6085-1, and Mageia issuing MGASA-2025-0260. A blog post by a MediaWiki developer (bawolff.net) discussed related XSS protector work around the same timeframe. No significant broader media coverage or notable researcher commentary specific to this CVE has been identified (Debian LTS Announce, Debian Security Announce).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45568CRITICAL9.9
  • Python logoPython
  • zrok
NoYesJul 16, 2026
CVE-2026-45576HIGH8.3
  • NixOS logoNixOS
  • zrok
NoYesJul 16, 2026
CVE-2026-36590HIGH7.5
  • NixOS logoNixOS
  • nanomq
NoNoJul 15, 2026
CVE-2026-59259MEDIUM6
  • NixOS logoNixOS
  • n8n
NoYesJul 15, 2026
CVE-2026-26032MEDIUM5.4
  • NixOS logoNixOS
  • ivy
NoYesJul 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management