Description
An issue in Dokuwiki v.2025-05-14b "Librarian" [56.2] allows a remote attacker to cause a denial of service via the media_upload_xhr() function in the media.php file
Published: 2026-04-03
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A remote attacker can cause a denial of service by exploiting a flaw in the media_upload_xhr() function within Dokuwiki’s media.php module. The vulnerability is reflected by resource exhaustion and potential memory exhaustion weaknesses, as identified by CWE-400 and CWE-770. When triggered, the request leads the application to become unresponsive, disrupting access for all users without compromising data confidentiality or integrity.

Affected Systems

Dokuwiki DokuWiki version 2025-05-14b is susceptible. No other versions are listed as affected in the available data.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests low exploitation probability. The vulnerability is not currently catalogued in the CISA KEV list. It is inferred that the attack vector is a remote HTTP request targeting the media_upload_xhr endpoint; no authentication prerequisites are stated, so a publicly accessible endpoint is likely sufficient. Because the conditions are easily met and the denial of service has wide impact, operators should consider rapid mitigation.

Generated by OpenCVE AI on April 9, 2026 at 01:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dokuwiki to the latest release that contains the fix for the media_upload_xhr() issue

Generated by OpenCVE AI on April 9, 2026 at 01:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Media Upload in Dokuwiki 2025-05-14b

Thu, 09 Apr 2026 00:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dokuwiki:dokuwiki:2025-05-14b:*:*:*:*:*:*:*

Wed, 08 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Title Denial of Service from Remote Media Upload in Dokuwiki 2025‑05‑14b

Wed, 08 Apr 2026 19:15:00 +0000

Type Values Removed Values Added
Description An issue in Dokuwiki v.2025-05-14b 'Librarian' allows a remote attacker to cause a denial of service via the media_upload_xhr() function in the media.php file An issue in Dokuwiki v.2025-05-14b "Librarian" [56.2] allows a remote attacker to cause a denial of service via the media_upload_xhr() function in the media.php file
References

Wed, 08 Apr 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Dokuwiki
Dokuwiki dokuwiki
Weaknesses CWE-770
CPEs cpe:2.3:a:dokuwiki:dokuwiki:*:*:*:*:*:*:*:*
Vendors & Products Dokuwiki
Dokuwiki dokuwiki
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Tue, 07 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Wiki
Wiki dokuwiki
Vendors & Products Wiki
Wiki dokuwiki

Fri, 03 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
Title Denial of Service from Remote Media Upload in Dokuwiki 2025‑05‑14b

Fri, 03 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
Description An issue in Dokuwiki v.2025-05-14b 'Librarian' allows a remote attacker to cause a denial of service via the media_upload_xhr() function in the media.php file
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-04-08T18:58:43.482Z

Reserved: 2026-02-16T00:00:00.000Z

Link: CVE-2026-26477

cve-icon Vulnrichment

Updated: 2026-04-03T15:01:26.182Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-03T15:16:05.093

Modified: 2026-04-09T00:16:15.910

Link: CVE-2026-26477

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-09T08:29:19Z

Weaknesses