Security readout for executives and security teams
Plain-English summary
CVE-2021-36125 is a denial-of-service issue in MediaWiki's CentralAuth extension. A rename-request page can enter infinite loops when a user's current username exceeds the configured MaxNameChars limit. The public bundle does not provide a CVSS score, confirmed fixed version, or evidence of active exploitation.
Executive priority
Treat this as a targeted availability risk for MediaWiki environments using CentralAuth. It is not currently evidenced as exploited in the provided sources, but public-facing wiki services should confirm exposure and apply vendor-supported remediation promptly.
Technical view
The issue affects Special:GlobalRenameRequest in the CentralAuth extension for MediaWiki through 1.36. The vulnerable condition involves usernames longer than the configured MaxNameChars value, causing infinite loop behavior and denial of service. The provided sources reference a Wikimedia Phabricator task and Gerrit change but do not include exploit details or complete remediation metadata.
Likely exposure
Exposure is most likely in MediaWiki deployments using the CentralAuth extension through 1.36, especially where Special:GlobalRenameRequest is reachable and accounts may have names longer than MaxNameChars. The bundle lists affected vendor/product fields as n/a, so inventory confirmation is required.
Exploitation context
The CVE is not listed as KEV, and the supplied sources do not state active exploitation. The plausible impact is availability disruption rather than data theft or code execution, based on the described infinite loop and denial-of-service behavior.
Researcher notes
Key missing data includes CVSS, CWE, exact affected product metadata, and named fixed versions. The Gerrit and Phabricator references appear central to remediation context, but the supplied bundle does not summarize their contents beyond linking them.
Mitigation direction
- Check Wikimedia and MediaWiki guidance for the applicable CentralAuth fix or upgrade path.
- Review the referenced Gerrit change before applying any source-level remediation.
- Confirm MaxNameChars configuration and identify existing accounts exceeding that limit.
- Restrict unnecessary access to rename-request workflows where operationally acceptable.
- Monitor the affected page for repeated errors, timeouts, or resource spikes.
Validation and detection
- Inventory MediaWiki versions and confirm whether CentralAuth is enabled.
- Check whether deployments are MediaWiki through 1.36 with CentralAuth present.
- Review configuration for MaxNameChars and compare against existing username lengths.
- Inspect application logs for Special:GlobalRenameRequest timeouts or repeated failures.
- Verify vendor remediation has been applied in a staging environment first.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-36125 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://phabricator.wikimedia.org/T260865CVE reference · x_refsource_MISC
- https://gerrit.wikimedia.org/r/q/I97d8b3236b5abed8ba9a9c4d3ab5050c2e782c22CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
