Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 483
Alerts This Week
Warning Icon 1 483

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 123 articles for you...
87

Debian MediaWiki Important Code Execution Info Issues DSA-6380-1

Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure, code execution via unsafe deserialisation or cross-site scripting. For the stable distribution (trixie), these problems have been fixed in version 1:1.43.9+dfsg-1~deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6380-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff July 05, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : mediawiki CVE ID : CVE-2026-58024 CVE-2026-58025 CVE-2026-58026 CVE-2026-58027 CVE-2026-58028 CVE-2026-58029 CVE-2026-58030 CVE-2026-58032 CVE-2026-58033 CVE-2026-58037 Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure, code execution via unsafe deserialisation or cross-site scripting. For the stable distribution (trixie), these problems have been fixed in version 1:1.43.9+dfsg-1~deb13u1. We recommend that you upgrade your mediawiki packages. For the detailed security status of mediawiki please refer to its security tracker page at: https://security-tracker.debian.org/tracker/mediawiki Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Security issues in MediaWiki were fixed in Debian 1:1.43.9+dfsg-1~deb13u1 to prevent information leakage.. Debian Security Advisory, MediaWiki Update, Code Execution Threat. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 05, 2026 Important Debian
197

Debian LTS MediaWiki DLA-4640-1 Access Control Bypass Issues

Multiple security vulnerabilities were found in mediawiki, a website engine for collaborative work, which could lead to information disclosure or access controls bypass. CVE-2026-34087 OATHAuth extension: Users API leaks whether privileged users have. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4640-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin June 22, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : mediawiki Version : 1:1.35.13-1+deb11u7 $bookworm_VERSION CVE ID : CVE-2026-34087 CVE-2026-34088 CVE-2026-34093 CVE-2026-34095 Multiple security vulnerabilities were found in mediawiki, a website engine for collaborative work, which could lead to information disclosure or access controls bypass. CVE-2026-34087 OATHAuth extension: Users API leaks whether privileged users have their user groups disabled for lack of 2FA. CVE-2026-34088 RecentChanges entries expose suppressed content via generated log page HTML. CVE-2026-34093 Special:UserRights page allows viewing user rights from private wiki. CVE-2026-34095 action=raw with Special:Mypage subpage title responds with "Content-Type: text/html" on ctype=text/javascript request, which may lead to cross-site scripting. For Debian 11 bullseye, these problems have been fixed in version 1:1.35.13-1+deb11u7. For Debian 12 bookworm, these problems have been fixed in version $bookworm_VERSION. We recommend that you upgrade your mediawiki packages. For the detailed security status of mediawiki please refer to its security tracker page at: https://security-tracker.debian.org/tracker/mediawiki Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Explore therecent Debian LTS advisory DLA-4640-1 addressing critical security issues in MediaWiki affecting access controls and user information.. Debian LTS MediaWiki security issues, access control bypass, information disclosure vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 21, 2026 Important Debian LTS
87

Debian DSA-6208-1 MediaWiki High Info Disclosure and Permission Issues

Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure or incomplete permission checks. For the oldstable distribution (bookworm), these problems have been fixed in version 1:1.39.17-1+deb12u2.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6208-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 12, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : mediawiki CVE ID : CVE-2026-34086 CVE-2026-34087 CVE-2026-34088 CVE-2026-34091 CVE-2026-34092 CVE-2026-34093 CVE-2026-34094 CVE-2026-34095 CVE-2026-5266 Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure or incomplete permission checks. For the oldstable distribution (bookworm), these problems have been fixed in version 1:1.39.17-1+deb12u2. For the stable distribution (trixie), these problems have been fixed in version 1:1.43.8+dfsg-1~deb13u1. We recommend that you upgrade your mediawiki packages. For the detailed security status of mediawiki please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/mediawiki Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Advisory DSA-6208-1 addresses multiple MediaWiki security issues leading to information exposure. Upgrade now.. Debian Advisory, MediaWiki Security, Information Disclosure, Permission Checks. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 12, 2026 Important Debian
197

Debian: MediaWiki Important Info Disclosure DLA-4428-1, CVE-2025-67475

Multiple security vulnerabilities were found in mediawiki, a website engine for collaborative work, which could lead to information disclosure, denial of service or privilege escalation. CVE-2025-67475 Square brackets in autocomment links were not always escaped.. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4428-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin December 30, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : mediawiki Version : 1:1.35.13-1+deb11u6 CVE ID : CVE-2025-67475 CVE-2025-67478 CVE-2025-67479 CVE-2025-67480 CVE-2025-67481 CVE-2025-67482 CVE-2025-67484 Multiple security vulnerabilities were found in mediawiki, a website engine for collaborative work, which could lead to information disclosure, denial of service or privilege escalation. CVE-2025-67475 Square brackets in autocomment links were not always escaped. CVE-2025-67478 Commas not separating values in RFC 2822 style headers were not escaped, hence could be interpreted downstream as value separators. CVE-2025-67479 Underscore and wide underscore were not always sanitized in `data-*` attribute names. CVE-2025-67480 ApiQueryRevisionsBase did not check for read permissions for the target page. CVE-2025-67481 Insufficient `style` attribute sanitation in client-side messages (jqueryMsg). As such attributes are difficult to sanitize properly (the logic needs to be updated constantly as new CSS features are developed by browser vendors) and their use cases in client-side messages are extremely rare, they are no longer allowed. If needed, `class` and `id` are still allowed, so these elements can be targeted by normal stylesheets. CVE-2025-67482 Scribunto extension: Segfault in unpack() with large integers affecting some builds of Lua. CVE-2025-67484 Cross-site scripting (XSS) vulnerability via xslt option for users with the "editinterface" permission. The xslt option is now disabled by default. If the former unsafe behavior is desired, is can be re-enabled by setting `$wgEnableUnsafeXsltOption` to true. For Debian 11 bullseye, these problems have been fixed in version 1:1.35.13-1+deb11u6. We recommend that you upgrade your mediawiki packages. For the detailed security status of mediawiki please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/mediawiki Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Multiple vulnerabilities found in mediawiki may lead to information disclosure, DoS or privilege escalation. Update recommended.. mediawiki security, Debian advisory, vulnerability patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 30, 2025 Important Debian LTS
203

Mageia 9: MediaWiki Critical XSS Denial of Service Fix MGASA-2025-0260

MGASA-2025-0260 - Updated mediawiki packages fix security vulnerabilities. MGASA-2025-0260 - Updated mediawiki packages fix security vulnerabilities Publication date: 05 Nov 2025 URL: https://advisories.mageia.org/MGASA-2025-0260.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-3469, CVE-2025-32696, CVE-2025-32697, CVE-2025-32698, CVE-2025-32699, CVE-2025-32700, CVE-2025-32072, CVE-2025-11173, CVE-2025-11261, CVE-2025-61635, CVE-2025-61638, CVE-2025-61639, CVE-2025-61640, CVE-2025-61641, CVE-2025-61643, CVE-2025-61646, CVE-2025-61653 Description: i18n XSS vulnerability in HTMLMultiSelectField when sections are used. (CVE-2025-3469) "reupload-own" restriction can be bypassed by reverting file. (CVE-2025-32696) Cascading protection is not preventing file reversions. (CVE-2025-32697) LogPager.php: Restriction enforcer functions do not correctly enforce suppression restrictions. (CVE-2025-32698) Potential javascript injection attack enabled by Unicode normalization in Action API. (CVE-2025-32699) AbuseFilter log interfaces expose global private and hidden filters when central DB is not available. (CVE-2025-32700) HTML injection in feed output from i18n message. (CVE-2025-32072) OATHAuth extension: Reauthentication for enabling 2FA can be bypassed by submitting a form in Special:OATHManage. (CVE-2025-11173) Stored i18n Cross-site scripting (XSS) vulnerability in mw.language.listToText. (CVE-2025-11261) ConfirmEdit extension: Missing rate limiting in ApiFancyCaptchaReload. (CVE-2025-61635) Parsoid: Validation bypass for `data-` attributes. (CVE-2025-61638) Log entries which are hidden from the creation of the entry may be disclosed to the public recent change entry. (CVE-2025-61639) Stored i18n Cross-site scripting (XSS) vulnerability in Special:RecentChangesLinked. (CVE-2025-61640) DDoS vulnerability in QueryAllPages API in miser mode. The `maxsize` value is now ignored in that mode. (CVE-2025-61641) Suppressed recentchanges may be disclosed to the public RCFeeds. (CVE-2025-61643) Public Watchlist/RecentChanges pages may disclose hidden usernames when an individual editor makes consecutive revisions on a single page, and only some are marked as hidden username. (CVE-2025-61646) TextExtracts extension: Information disclosure vulnerability in the extracts API action endpoint due to missing read permission check. (CVE-2025-61653) VisualEditor extension: Stored i18n Cross-site scripting (XSS) vulnerability in `lastModifiedAt` system messages. (CVE-2025-61655) VisualEditor extension: Missing attribute validation for attributes unwrapped from `data-ve-attributes`. (CVE-2025-61656) References: - https://bugs.mageia.org/show_bug.cgi?id=34211 - https://lists.debian.org/debian-security-announce/2025/msg00063.html - https://lists.wikimedia.org/hyperkitty/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/CIXFJVC57OFRBCCEIDRLZCLFGMYGEYTT/ - https://lists.debian.org/debian-security-announce/2025/msg00121.html - https://lists.debian.org/debian-lts-announce/2025/10/msg00034.html - https://www.cve.org/CVERecord?id=CVE-2025-3469 - https://www.cve.org/CVERecord?id=CVE-2025-32696 - https://www.cve.org/CVERecord?id=CVE-2025-32697 - https://www.cve.org/CVERecord?id=CVE-2025-32698 - https://www.cve.org/CVERecord?id=CVE-2025-32699 - https://www.cve.org/CVERecord?id=CVE-2025-32700 - https://www.cve.org/CVERecord?id=CVE-2025-32072 - https://www.cve.org/CVERecord?id=CVE-2025-11173 - https://www.cve.org/CVERecord?id=CVE-2025-11261 - https://www.cve.org/CVERecord?id=CVE-2025-61635 - https://www.cve.org/CVERecord?id=CVE-2025-61638 - https://www.cve.org/CVERecord?id=CVE-2025-61639 - https://www.cve.org/CVERecord?id=CVE-2025-61640 - https://www.cve.org/CVERecord?id=CVE-2025-61641 - https://www.cve.org/CVERecord?id=CVE-2025-61643 - https://www.cve.org/CVERecord?id=CVE-2025-61646 - https://www.cve.org/CVERecord?id=CVE-2025-61653 SRPMS: - 9/core/mediawiki-1.35.14-1.1.mga9 . Security advisory for Mageia mediawiki package addresses multiple criticalvulnerabilities. Immediate updates recommended.. Mageia Security Advisory, MediaWiki Updates, Critical Security Fixes, XSS Protection Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 05, 2025 Critical Mageia
197

Debian 11 MediaWiki Important Security Advisory DLA-4249-1 CVE-2025-3469

Multiple security vulnerabilities were found in mediawiki, a website engine for collaborative work, that could lead to information disclosure or privilege escalation. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4249-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin July 23, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : mediawiki Version : 1:1.35.13-1+deb11u4 CVE ID : CVE-2025-3469 CVE-2025-6590 CVE-2025-6591 CVE-2025-6593 CVE-2025-6594 CVE-2025-6595 CVE-2025-6597 CVE-2025-6926 CVE-2025-32072 CVE-2025-32696 CVE-2025-32698 CVE-2025-32699 Multiple security vulnerabilities were found in mediawiki, a website engine for collaborative work, that could lead to information disclosure or privilege escalation. CVE-2025-3469 User input was not properly sanitized during web page generation, which could lead to information disclosure or privilege escalation via Cross-site Scripting. CVE-2025-6590 User input was not sanitized in the password reset form, which could lead to information disclosure for private pages via transclusion. CVE-2025-6591 HTML injection in API `action=feedcontributions` output from i18n messages. CVE-2025-6593 "{{SITENAME}} registered email address has been changed" email was sent to unverified email addresses, which could lead to information disclosure. CVE-2025-6594 XSS in Special:ApiSandbox. While the known issue is not exploitable in ≤1.39, the backported changes provide some security hardening just in case. CVE-2025-6595 Stored XSS through system messages in MultimediaViewer. CVE-2025-6597 Autocreation was treated as login for the purposes of security reauthentication. However itdoesn't necessarily involve real-time user identification, as it can be based on some provider identifying the user based on a session cookie or similar low-fidelity information. An attacker who got hold of a CentralAuth session cookie (valid on any wiki) could just visit a wiki where the user has no local account yet, get an account autocreated, and then change credentials or perform other sensitive operations. CVE-2025-6926 Allow extensions to suppress the reauth flag on login. This is a workaround for extensions with some sort of "autologin" implemented via the login page to indicate that the login flow didn't involve the user actually logging in, it merely copied some central login state, and so isn't appropriate for the reauthentication flag. CVE-2025-32072 HTML injection in feed output from i18n message. CVE-2025-32696 "reupload-own" restriction could be bypassed by reverting file. CVE-2025-32698 Improper enforcing of suppression restrictions in LogPager.php. CVE-2025-32699 Potential javascript injection attack enabled by Unicode normalization in Action API. For Debian 11 bullseye, these problems have been fixed in version 1:1.35.13-1+deb11u4. We recommend that you upgrade your mediawiki packages. For the detailed security status of mediawiki please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/mediawiki Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Numerous vulnerabilities in MediaWiki pose threats of data breaches and unauthorized privilege increases; prompt updates advised.. Debian Security, mediawiki update, privilege escalation, information disclosure. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 23, 2025 Important Debian LTS
87

Debian: DSA-5957-1 mediawiki critical: XSS and info disclosure issues

Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in cross-site scripting, information disclosure, HTML injection or incorrect tracking of authentication events. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5957-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff July 03, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : mediawiki CVE ID : CVE-2025-6590 CVE-2025-6591 CVE-2025-6593 CVE-2025-6594 CVE-2025-6595 CVE-2025-6597 CVE-2025-6926 CVE-2025-32072 Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in cross-site scripting, information disclosure, HTML injection or incorrect tracking of authentication events. For the stable distribution (bookworm), these problems have been fixed in version 1:1.39.13-1~deb12u1. We recommend that you upgrade your mediawiki packages. For the detailed security status of mediawiki please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/mediawiki Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent Debian DSA-5958-2 addresses vital vulnerabilities in MediaWiki. It's crucial to maintain the latest version to safeguard against potential XSS attacks and additional threats.. Debian, MediaWiki, Cross-Site Scripting, Security Issues, Information Disclosure. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 03, 2025 Critical Debian
89

Fedora 42: FEDORA-2025-01bd4e4d20 critical: mediawiki upgrade

https://lists.wikimedia.org/hyperkitty/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/OXIGQIHBL26HFKG6TT5SWSH7K7W6RO4H/ https://phabricator.wikimedia.org/T382326 . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-01bd4e4d20 2025-06-22 05:57:57.824370+00:00 -------------------------------------------------------------------------------- Name : mediawiki Product : Fedora 42 Version : 1.43.1 Release : 1.fc42 URL : https://www.mediawiki.org/wiki/MediaWiki Summary : A wiki engine Description : MediaWiki is the software used for Wikipedia and the other Wikimedia Foundation websites. Compared to other wikis, it has an excellent range of features and support for high-traffic websites using multiple servers This package supports wiki farms. Read the instructions for creating wiki instances under /usr/share/doc/mediawiki/README.RPM. Remember to remove the config dir after completing the configuration. -------------------------------------------------------------------------------- Update Information: https://lists.wikimedia.org/hyperkitty/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/OXIGQIHBL26HFKG6TT5SWSH7K7W6RO4H/ https://phabricator.wikimedia.org/T382326 -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 12 2025 Michael Cronenworth - 1.43.1-1 - Update to 1.43.1 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-01bd4e4d20' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Update your MediaWiki installation on Fedora 42, implementing essential patches to improve both security and performance. Ensure robust support for high-traffic scenarios.. mediawiki upgrade, Fedora security, running mediawiki, security advisory, critical fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 22, 2025 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200