CVE-2025-67478
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-67478 is a vulnerability in the Wikimedia Foundation's CheckUser MediaWiki extension, specifically associated with the includes/Mail/UserMailer.php file. It affects CheckUser versions from 1.39.0 before 1.39.14, 1.43.0 before 1.43.4, and 1.44.0 before 1.44.1. The vulnerability was published on February 3, 2026, and carries a CVSS v3.1 base score of 8.8 (High), requiring user interaction but no authentication (Red Hat CVE, Feedly). A technical write-up describing the issue as "wrong e-mail address composition for usernames with a comma and umlauts" has been published (infinitsec).

Technical details

The vulnerability resides in includes/Mail/UserMailer.php within the CheckUser extension and relates to improper construction of email addresses for usernames containing special characters such as commas and umlauts. This malformed email address composition can be exploited by an unauthenticated network attacker when a user interacts with the affected functionality, suggesting a potential email header injection or address spoofing scenario. The root cause appears to be insufficient sanitization or encoding of special characters in username-derived email fields (infinitsec, Phabricator). The associated Wikimedia task is tracked at Phabricator T385403 (Phabricator).

Impact

Successful exploitation of CVE-2025-67478 can result in high impact to confidentiality, integrity, and availability of affected CheckUser installations, as reflected in the CVSS v3.1 scoring. An unauthenticated attacker leveraging this vulnerability via network access — with user interaction as a precondition — could potentially manipulate email communications, expose sensitive user data handled by the CheckUser extension, or disrupt the extension's functionality (Red Hat CVE, Feedly). Given that CheckUser is used by wiki administrators to investigate user activity, compromise of this component could expose sensitive investigative data about users.

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.063%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Mitigation and workarounds

Organizations should upgrade the CheckUser MediaWiki extension to the patched versions: 1.39.14 or later for the 1.39.x branch, 1.43.4 or later for the 1.43.x branch, or 1.44.1 or later for the 1.44.x branch (Red Hat CVE, Phabricator). Debian has also issued security advisories (DSA-6085-1 and DLA-4428-1) for affected MediaWiki packages (Debian Security, Debian LTS). If immediate patching is not feasible, consider temporarily restricting access to CheckUser functionality as a workaround.

Community reactions

Debian issued security advisories DSA-6085-1 and DLA-4428-1 addressing this and related MediaWiki vulnerabilities (Debian Security, Debian LTS). Tenable published Nessus detection plugins (IDs 278533 and 279440) for the vulnerability. A researcher at infinitsec published a technical description characterizing the issue as incorrect email address composition for usernames with commas and umlauts (infinitsec). No significant social media discussion or major media coverage has been identified.

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78683CRITICAL9.4
  • Linux Debian logoLinux Debian
  • nltk
NoYesAug 25, 2026
CVE-2026-78682HIGH8.7
  • Linux Debian logoLinux Debian
  • nltk
NoYesAug 25, 2026
CVE-2026-78681HIGH8.7
  • Linux Debian logoLinux Debian
  • nltk
NoYesAug 25, 2026
CVE-2026-78680HIGH8.5
  • Linux Debian logoLinux Debian
  • nltk
NoYesAug 25, 2026
CVE-2026-78679HIGH7.1
  • Linux Debian logoLinux Debian
  • python-git
NoNoAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management