Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96924.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-96924
Upstream
  • CVE-2026-77643
Published
2026-08-20T22:18:06Z
Modified
2026-09-20T05:32:18Z
Summary
CVE-2026-77643 affecting package xapian-core 1.4.26-2
Details

A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499.

References

Affected packages

Azure Linux:3 / xapian-core

Package

Name
xapian-core
Purl
pkg:rpm/azure-linux/xapian-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.4.26-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96924.json"