XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apache Allura: from 1.10.0 before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.
Info
Summary
XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apache Allura: from 1.10.0 before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://allura.apache.org/posts/2026-allura-1.19.1.html
- https://lists.apache.org/thread/p7bd1yz9v9wbsbc6hz3tjxozxnwyzqz0
- http://www.openwall.com/lists/oss-security/2026/08/12/16
Timeline
- nvd_ingest NVD