Unrated severityNVD Advisory· Published Jul 1, 2026· Updated Jul 1, 2026
UrlShortener extension url validation can be bypassed due to difference between php url parsing and WHATWG
CVE-2026-13706
Description
Improper input validation vulnerability in Wikimedia Foundation UrlShortener.
This vulnerability is associated with program files includes/UrlShortenerUtils.Php.
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.