Moodle TeX formula editor is vulnerable to DoS through lack of execution time limits
Moderate severity
GitHub Reviewed
Published
Feb 21, 2026
to the GitHub Advisory Database
•
Updated Feb 27, 2026
Package
Affected versions
>= 5.1.0-beta, < 5.1.2
>= 5.0.0-beta, < 5.0.5
< 4.5.9
Patched versions
5.1.2
5.0.5
4.5.9
Description
Published by the National Vulnerability Database
Feb 21, 2026
Published to the GitHub Advisory Database
Feb 21, 2026
Reviewed
Feb 25, 2026
Last updated
Feb 27, 2026
A Denial of Service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server resources. An authenticated user could abuse this behavior to degrade performance or cause service interruption.
References