XSS vulnerability in code display in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.
Info
Summary
XSS vulnerability in code display in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://allura.apache.org/posts/2026-allura-1.19.1.html
- https://lists.apache.org/thread/bbzhnvqlwvwbprnfg4g41s8wkc5bdfmk
- http://www.openwall.com/lists/oss-security/2026/08/12/17
Timeline
- nvd_ingest NVD