CVE-2021-41118 - CVE House
Back to Database
Status published Medium CVE-2021-41118

ReDoS in DynamicPageList3

Vulnerability Description

The DynamicPageList3 extension is a reporting tool for MediaWiki, listing category members and intersections with various formats and details. In affected versions unsanitised input of regular expression date within the parameters of the DPL parser function, allowed for the possibility of ReDoS (Regex Denial of Service). This has been resolved in version 3.3.6. If you are unable to update you may also set `$wgDplSettings['functionalRichness'] = 0;` or disable DynamicPageList3 to mitigate.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-41118

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Universal-Omega

View all reports →

Affected Software

DynamicPageList3
Vulnerable Versions:
< 3.3.6

Timeline

Official Publish: October 4th, 2021
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

Weaknesses (CWE)