SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. An attacker can inject arbitrary JavaScript which will execute upon a target user navigating to a crafted, malicious link. Fixed in 10.12.2 and 10.9.3.
{
"cna_assigner": "cisa-cg",
"cwe_ids": [
"CWE-79"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66300.json"
}"2026-08-06T08:28:42Z"
[
{
"target": {
"file": "src/main/java/org/snomed/snowstorm/rest/WebRouteController.java"
},
"digest": {
"line_hashes": [
"312121057209247412561371746165427801910",
"123767059360933163767147935243888121600",
"245015302850170211236757456522837854582",
"265694949697940524124620988879311909521",
"194411002063778391076307791763018993394",
"241092865177827865429717117285236448938",
"173215006743254760077072466821569263509",
"105162729147787610127422201836441706337",
"285161036326361483053192775125343555417",
"156223145217900194020324385190719278086",
"132512299102570733574836108290291065542",
"220616026381048562317001045910114325221",
"121977656371723106385613621269169436800",
"295273920552171663191117767466069287522"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-66300-2ad16563",
"source": "https://github.com/ihtsdo/snowstorm/commit/575b555695811110dafe2fcea7dd2fd7e4bcee39"
},
{
"target": {
"function": "issueRedirect",
"file": "src/main/java/org/snomed/snowstorm/rest/WebRouteController.java"
},
"digest": {
"length": 617.0,
"function_hash": "66705611246460464664973953452139273591"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2026-66300-4bbd4d38",
"source": "https://github.com/ihtsdo/snowstorm/commit/b8061add427c930b3030549e77aa23ec5957ceb6"
},
{
"target": {
"file": "src/main/java/org/snomed/snowstorm/rest/WebRouteController.java"
},
"digest": {
"line_hashes": [
"312121057209247412561371746165427801910",
"123767059360933163767147935243888121600",
"245015302850170211236757456522837854582",
"265694949697940524124620988879311909521",
"194411002063778391076307791763018993394",
"241092865177827865429717117285236448938",
"173215006743254760077072466821569263509",
"105162729147787610127422201836441706337",
"285161036326361483053192775125343555417",
"156223145217900194020324385190719278086",
"132512299102570733574836108290291065542",
"220616026381048562317001045910114325221",
"121977656371723106385613621269169436800",
"295273920552171663191117767466069287522"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-66300-83dd5f56",
"source": "https://github.com/ihtsdo/snowstorm/commit/b8061add427c930b3030549e77aa23ec5957ceb6"
},
{
"target": {
"function": "issueRedirect",
"file": "src/main/java/org/snomed/snowstorm/rest/WebRouteController.java"
},
"digest": {
"length": 617.0,
"function_hash": "66705611246460464664973953452139273591"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2026-66300-adaee01a",
"source": "https://github.com/ihtsdo/snowstorm/commit/575b555695811110dafe2fcea7dd2fd7e4bcee39"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66300.json"