🔐 CVE Alert

CVE-2026-85229

UNKNOWN 0.0

Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Booster UI. This issue affects Apache SkyWalking UI : from 10.2.0 through 10.4.0. Users are recommended to upgrade to Horizon UI 1.0.0, which fixes the issue.

CWE CWE-79
Vendor apache software foundation
Product apache skywalking
Published Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache skywalking

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache skywalking are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache SkyWalking
10.2.0 ≤ 10.4.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
lists.apache.org: https://lists.apache.org/thread/oswo0kxr7g2jgdoz3wd923nslo36jsv8

Credits

🔍 n0mi1k