Impact
A regular‑expression in YesWiki’s wakka.php formatter processes markdown links with an O(n^2) algorithm. The flaw allows an unauthenticated attacker to send a small payload of bracket characters to the edit‑preview endpoint, causing PHP‑FPM workers to become pinned and exhausting the pool. The result is a denial of service that can prevent legitimate users from accessing the web application. The weakness is reflected in CWE‑1333.
Affected Systems
YesWiki installations before version 4.6.7 are vulnerable. The issue affects all releases up to and including 4.6.6, regardless of operating system or PHP version, as long as the default wakka.php formatter is in use.
Risk and Exploitability
The CVSS score is 6.9, indicating medium severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Attackers do not need authentication; the exploit requires only the ability to post data to the public edit‑preview endpoint, typically over HTTP. The attack path is simple and can be triggered from any network that can reach the vulnerable application, making exploitation likely for exposed deployments.
OpenCVE Enrichment