Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure.This issue affects non release branches.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 07 Apr 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure.This issue affects non release branches. | |
| Title | Global vanishing does not completely remove user email | |
| Weaknesses | CWE-212 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: wikimedia-foundation
Published:
Updated: 2026-04-07T21:44:46.515Z
Reserved: 2026-04-07T21:25:36.589Z
Link: CVE-2026-39937
No data.
Status : Received
Published: 2026-04-07T22:16:24.283
Modified: 2026-04-07T22:16:24.283
Link: CVE-2026-39937
No data.
OpenCVE Enrichment
No data.
Weaknesses