Sceawere
Vulnerability Detail
CVE-2026-104454UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
YesWiki Algorithmic Complexity DoS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 11h ago
- Vendor
- YesWiki
- Product
- yeswiki
- Attack Type
- Inefficient Regular Expression Complexity
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
YesWiki before 4.6.7 contains an algorithmic-complexity denial of service in the wakka.php formatter due to an O(n^2) markdown-link regex. Unauthenticated attackers can submit a small crafted body of bracket characters to the page-edit preview endpoint to pin PHP-FPM workers and saturate the pool.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-02T12:17:17.160Z",
"pubdate": "2026-10-02T12:17:17.160Z",
"executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to an algorithmic complexity denial of service vulnerability triggered via the page-edit preview feature.\nThe vulnerability resides in the wakka.php formatter, which utilizes a regular expression for markdown-link parsing that exhibits O(n^2) time complexity.\nBy submitting a maliciously crafted sequence of bracket characters, an unauthenticated attacker can induce excessive CPU consumption during the regex evaluation process.\nThis behavior leads to the exhaustion of PHP-FPM workers, effectively saturating the server's resource pool and causing a denial of service for legitimate users.\nGiven that the exploit is achievable without authentication and targets the core rendering engine of the application, it poses a significant risk to service availability.\nSuccessful exploitation allows a remote attacker to crash or hang the web server process by sending a relatively small, specially formatted payload.",
"technicalDetails": "The vulnerability is rooted in an inefficient regular expression pattern implemented within the wakka.php file, which is responsible for the formatting and rendering of markdown links in YesWiki.\nThe regex engine, when processing specific nested or repetitive patterns involving bracket characters, enters a state of catastrophic backtracking. Because the regex implementation scales at O(n^2) complexity, the computational cost grows exponentially relative to the length and structure of the input string.\nAn unauthenticated attacker can exploit this by directing a crafted payload to the page-edit preview endpoint of the YesWiki installation.\nWhen the server attempts to render the preview of the malicious input, the PCRE engine becomes stalled while attempting to resolve the complex bracket sequences. This process consumes 100% of the available CPU cycles on the underlying PHP-FPM worker process.\nBecause PHP-FPM operates with a fixed number of child processes, a single attacker can saturate the entire worker pool by issuing a small number of concurrent requests, each containing the malicious regex payload.\nOnce the pool is exhausted, subsequent incoming requests from legitimate users are placed in a queue or rejected entirely, resulting in an effective denial of service across the application.\nThe vulnerability affects all versions of YesWiki prior to 4.6.7. The impact is limited to resource exhaustion and service unavailability; there is no indication of remote code execution or unauthorized data access associated with this specific flaw.\nThe exposure is network-based, as the page-edit preview functionality is publicly accessible by default, requiring no specific administrative or user privileges to trigger the rendering process."
}