What is CVE-2026-73238?
This is an XSS (Cross-Site Scripting) vulnerability discovered in the code display functionality of Apache Allura. It affects all versions prior to 1.19.1. Users are strongly recommended to upgrade to version 1.19.1 to fix the issue.
Azərbaycanca: Apache Allura proqram təminatında kod göstərmə funksiyasında aşkarlanan XSS (Cross-Site Scripting) zəifliyidir. Bu boşluq 1.19.1 versiyasından əvvəlki bütün versiyaları təsir edir. İstifadəçilərə bu problemi aradan qaldırmaq üçün dərhal 1.19.1 versiyasına yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Apache
FAQ2
Which versions of Apache Allura are affected by CVE-2026-73238?
This XSS vulnerability affects all versions of Apache Allura prior to version 1.19.1.
How can I fix the CVE-2026-73238 vulnerability?
To fix the vulnerability, it is strongly recommended to immediately upgrade Apache Allura to version 1.19.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.