CVE-2026-58520: UrlShortener defaults to ineffective validation open to third-party redirects
Published Jul 1, 2026
·Updated
URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener Extension allows Cross-Site Flashing.
This issue affects Mediawiki - UrlShortener Extension: from before 1.43.9, 1.44.6, 1.45.4.
Affected Software
4 affected components
The Wikimedia Foundation Mediawiki - UrlShortener Extension><=1.43.9, =1.44.6, =1.45.4
MediaWiki MediaWiki>=1.43.0<1.43.9
MediaWiki MediaWiki>=1.44.0<1.44.6
MediaWiki MediaWiki>=1.45.0<1.45.4
Event History
Jul 1, 2026
CVE Published
via MITRE·05:14 PM
Data Sourced
via MITRE·05:14 PM
DescriptionWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-58520?
CVE-2026-58520 has a medium severity rating of 6.9 according to the CVSS metrics.
2
How do I fix CVE-2026-58520?
To fix CVE-2026-58520, upgrade the Mediawiki UrlShortener Extension to versions 1.43.9, 1.44.6, or 1.45.4 or later.
3
What type of vulnerability is CVE-2026-58520?
CVE-2026-58520 is an open redirect vulnerability that allows URL redirection to untrusted sites.
4
Which software is impacted by CVE-2026-58520?
CVE-2026-58520 affects the Mediawiki - UrlShortener Extension used by The Wikimedia Foundation.
5
How does CVE-2026-58520 affect users?
CVE-2026-58520 can lead to Cross-Site Flashing attacks, potentially compromising user security.