Skip to main content

Wikimedia Foundation OATHAuth MediaWiki Module

Type

Security review

Client

The Wikimedia Foundation

Date

2026-08

Domain

AppSec

Effort

4.6 wks

Section

Technology Product Reviews

Trail of Bits's security review of The Wikimedia Foundation (Aug 2026) identified 33 issues: 2 high, 9 medium, 6 low, and 16 informational.

Findings · 33

  1. 1 Recovery codes with attached data are stored in plaintext Informational
  2. 2 Nonce reuse in recovery code encryption Low
  3. 3 Plaintext secrets are accepted when at-rest encryption is enabled Medium
  4. 4 Encrypted 2FA secrets can be swapped between users Medium
  5. 5 Lenient Base32 decoding in dependency christian-riesen/base32 Informational
  6. 6 The jakobo/hotp-php library does not fully implement RFC 6238 Informational
  7. 7 The DisableOATHForUser special page does not enforce sitewide blocks Medium
  8. 8 WikiText markup can be injected on the OATHManage special page Informational
  9. 9 TOTP resistance decreases with the number of registered authenticators Medium
  10. 10 Missing CSRF token on ApiQueryOATH can enable XS-Leaks on other user’s 2FA status Low
  11. 11 The disableoath rate limit counter is never incremented Low
  12. 12 Obsolete ApiOATHValidate endpoint exposes a TOTP validation oracle Informational
  13. 13 Incomplete notifications and logging for security-sensitive 2FA operations Informational
  14. 14 TOTP enrollment secret persists in session for full session lifetime Informational
  15. 15 Unbounded recovery code generation via Recover2FAForUser Informational
  16. 16 TOCTOU window on the badoath rate limiter allows extra verification attempts Medium
  17. 17 CredentialForm.getErrorText falls back to rendering raw strings as HTML Informational
  18. 18 Disable action bypasses mandatory 2FA enforcement, allowing downgrade to recovery codes only Informational
  19. 19 Unbounded resource consumption in spomky-labs/cbor-php High
  20. 20 Passkey registration mode is client-controlled and unenforced server-side Informational
  21. 21 Deprecated SHA-1 algorithm accepted for WebAuthn ceremonies Informational
  22. 22 No minimum RSA key size enforced for WebAuthn credentials Medium
  23. 23 WebAuthn origin validation ignores the port component Informational
  24. 24 WebAuthn challenges are valid for 24 hours Informational
  25. 25 WebAuthn credential ID is not checked for cross-user uniqueness Low
  26. 26 TOTP rate limiting and replay protection fail open when there is no persistent cache backend and during outages Medium
  27. 27 Bot password sessions bypass reauthentication for credential changes High
  28. 28 Disabling 2FA does not require proof of the second factor Medium
  29. 29 WebAuthn sign counter is never persisted after authentication Low
  30. 30 2FA session flag persists after 2FA is disabled Medium
  31. 31 Recovery code verification and consumption are not atomic Low
  32. 32 SecuritySensitiveOperationStatus hook can downgrade reauthentication requirements Informational
  33. 33 WebAuthn API endpoints disclose credential metadata without reauthentication Informational

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related