CVE-2026-34095: action=raw with Special:Mypage subpage title responds with "Content-Type: text/html" on ctype=text/javascript request
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Actions/ActionEntryPoint.Php, includes/Request/FauxResponse.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34095?
CVE-2026-34095 has been classified as a moderate severity vulnerability affecting specific versions of MediaWiki.
How do I fix CVE-2026-34095?
To fix CVE-2026-34095, upgrade to MediaWiki version 1.43.8, 1.44.5, or 1.45.3 or later.
What is the impact of CVE-2026-34095?
The impact of CVE-2026-34095 may lead to content being exposed as HTML instead of the expected JavaScript, potentially causing unsafe script execution.
Which versions of MediaWiki are affected by CVE-2026-34095?
CVE-2026-34095 affects MediaWiki versions up to 1.43.7, 1.44.4, and 1.45.2.
Is there a workaround for CVE-2026-34095?
There are no official workarounds for CVE-2026-34095; upgrading to the fixed versions is recommended.