Description
YesWiki before 4.6.7 contains an algorithmic-complexity denial of service in the wakka.php formatter due to an O(n^2) markdown-link regex. Unauthenticated attackers can submit a small crafted body of bracket characters to the page-edit preview endpoint to pin PHP-FPM workers and saturate the pool.
Published: 2026-10-02
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via algorithmic complexity
Action: Patch
AI Analysis

Impact

A regular‑expression in YesWiki’s wakka.php formatter processes markdown links with an O(n^2) algorithm. The flaw allows an unauthenticated attacker to send a small payload of bracket characters to the edit‑preview endpoint, causing PHP‑FPM workers to become pinned and exhausting the pool. The result is a denial of service that can prevent legitimate users from accessing the web application. The weakness is reflected in CWE‑1333.

Affected Systems

YesWiki installations before version 4.6.7 are vulnerable. The issue affects all releases up to and including 4.6.6, regardless of operating system or PHP version, as long as the default wakka.php formatter is in use.

Risk and Exploitability

The CVSS score is 6.9, indicating medium severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Attackers do not need authentication; the exploit requires only the ability to post data to the public edit‑preview endpoint, typically over HTTP. The attack path is simple and can be triggered from any network that can reach the vulnerable application, making exploitation likely for exposed deployments.

Generated by OpenCVE AI on October 2, 2026 at 12:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade YesWiki to version 4.6.7 or newer to eliminate the O(n^2) regex flaw
  • If an upgrade cannot be applied immediately, apply rate limiting or request throttling to the edit‑preview endpoint to prevent saturation of PHP‑FPM workers
  • Configure PHP‑FPM to cap the maximum number of child processes or adjust resource limits so that a single worker’s pinning has minimal effect on overall availability

Generated by OpenCVE AI on October 2, 2026 at 12:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description YesWiki before 4.6.7 contains an algorithmic-complexity denial of service in the wakka.php formatter due to an O(n^2) markdown-link regex. Unauthenticated attackers can submit a small crafted body of bracket characters to the page-edit preview endpoint to pin PHP-FPM workers and saturate the pool.
Title YesWiki before 4.6.7 ReDoS via wakka.php Edit-Preview Endpoint
First Time appeared Yeswiki
Yeswiki yeswiki
Weaknesses CWE-1333
CPEs cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Vendors & Products Yeswiki
Yeswiki yeswiki
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T14:50:11.572Z

Reserved: 2026-10-02T00:53:58.504Z

Link: CVE-2026-104454

cve-icon Vulnrichment

Updated: 2026-10-02T14:49:49.847Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:17.160

Modified: 2026-10-02T15:17:07.570

Link: CVE-2026-104454

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:30:05Z

Weaknesses
  • CWE-1333

    Inefficient Regular Expression Complexity