CVE-2026-26047: Moodle: moodle: uncontrolled resource consumption in tex formula editor leading to denial of service
A Denial of Service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server resources. An authenticated user could abuse this behavior to degrade performance or cause service interruption.
Other sources
A Denial-of-Service vulnerability exists in Moodle’s TeX formula editor due to missing execution time controls during TeX rendering with mimetex. An authenticated user can submit specially crafted TeX content that causes excessive CPU consumption, resulting in degraded performance or service outage. While confidentiality and integrity are not impacted, availability of the Moodle instance may be significantly affected.
— Red Hat
A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server resources. An authenticated user could abuse this behavior to degrade performance or cause service interruption.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26047?
CVE-2026-26047 is classified as a high-severity Denial-of-Service vulnerability.
How do I fix CVE-2026-26047?
To fix CVE-2026-26047, you should update your Moodle installation to the latest version where this vulnerability has been patched.
Who is affected by CVE-2026-26047?
CVE-2026-26047 affects all authenticated users of Moodle who have access to the TeX formula editor.
What type of vulnerability is CVE-2026-26047?
CVE-2026-26047 is an uncontrolled resource consumption vulnerability leading to potential denial of service.
What impact does CVE-2026-26047 have on Moodle users?
CVE-2026-26047 may allow authenticated users to exhaust system resources, causing service disruption for other users.