Description
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. A denial of service (resource consumption) can be accomplished by searching for a very long key in a Language Name Search.
Remediation
References
Related Vulnerabilities
Moodle Uncontrolled Resource Consumption Vulnerability (CVE-2021-32476)
Squid Improper Input Validation Vulnerability (CVE-2016-2570)
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-17303)
Apache Tomcat Improper Encoding or Escaping of Output Vulnerability (CVE-2021-30640)