CVE-2026-58028
Publication date 1 July 2026
Last updated 1 July 2026
Ubuntu priority
Description
[Disallow user JS in pretty-print api.php responses]
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| mediawiki | 26.04 LTS resolute |
Needs evaluation
|
| 25.10 questing |
Needs evaluation
|
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2026-58028
- http://phabricator.wikimedia.org/T422306
- https://gerrit.wikimedia.org/r/c/mediawiki/core/+/1306211 (master)
- https://gerrit.wikimedia.org/r/c/mediawiki/extensions/CentralAuth/+/1306216 (master)
- https://gerrit.wikimedia.org/r/c/mediawiki/core/+/1306308 (REL1_43)
- https://gerrit.wikimedia.org/r/c/mediawiki/extensions/CentralAuth/+/1306320 (REL1_43)