LiveActive security incident?Get immediate response
CVE Record

CVE-2021-36125: An issue was discovered in the CentralAuth extension in MediaWiki through 1.36.

An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalRenameRequest page is vulnerable to infinite loops and denial of service attacks when a user's current username is beyond an arbitrary maximum configuration value (MaxNameChars).

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2021-36125 is a denial-of-service issue in MediaWiki's CentralAuth extension. A rename-request page can enter infinite loops when a user's current username exceeds the configured MaxNameChars limit. The public bundle does not provide a CVSS score, confirmed fixed version, or evidence of active exploitation.

Executive priority

Treat this as a targeted availability risk for MediaWiki environments using CentralAuth. It is not currently evidenced as exploited in the provided sources, but public-facing wiki services should confirm exposure and apply vendor-supported remediation promptly.

Technical view

The issue affects Special:GlobalRenameRequest in the CentralAuth extension for MediaWiki through 1.36. The vulnerable condition involves usernames longer than the configured MaxNameChars value, causing infinite loop behavior and denial of service. The provided sources reference a Wikimedia Phabricator task and Gerrit change but do not include exploit details or complete remediation metadata.

Likely exposure

Exposure is most likely in MediaWiki deployments using the CentralAuth extension through 1.36, especially where Special:GlobalRenameRequest is reachable and accounts may have names longer than MaxNameChars. The bundle lists affected vendor/product fields as n/a, so inventory confirmation is required.

Exploitation context

The CVE is not listed as KEV, and the supplied sources do not state active exploitation. The plausible impact is availability disruption rather than data theft or code execution, based on the described infinite loop and denial-of-service behavior.

Researcher notes

Key missing data includes CVSS, CWE, exact affected product metadata, and named fixed versions. The Gerrit and Phabricator references appear central to remediation context, but the supplied bundle does not summarize their contents beyond linking them.

Mitigation direction

  • Check Wikimedia and MediaWiki guidance for the applicable CentralAuth fix or upgrade path.
  • Review the referenced Gerrit change before applying any source-level remediation.
  • Confirm MaxNameChars configuration and identify existing accounts exceeding that limit.
  • Restrict unnecessary access to rename-request workflows where operationally acceptable.
  • Monitor the affected page for repeated errors, timeouts, or resource spikes.

Validation and detection

  • Inventory MediaWiki versions and confirm whether CentralAuth is enabled.
  • Check whether deployments are MediaWiki through 1.36 with CentralAuth present.
  • Review configuration for MaxNameChars and compare against existing username lengths.
  • Inspect application logs for Special:GlobalRenameRequest timeouts or repeated failures.
  • Verify vendor remediation has been applied in a staging environment first.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-36125 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.