DEBIAN-CVE-2026-77643

Source
https://security-tracker.debian.org/tracker/CVE-2026-77643
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-77643.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-77643
Upstream
  • CVE-2026-77643
Published
2026-08-20T22:18:06.207Z
Modified
2026-08-21T05:02:10.259740841Z
Severity
  • 4.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499.

References

Affected packages

Debian:11 / xapian-core

Package

Name
xapian-core
Purl
pkg:deb/debian/xapian-core?arch=source&distro=bullseye

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.4.18-3
1.4.18-3+deb11u1
1.4.18-4
1.4.20-1
1.4.20-2
1.4.21-1
1.4.22-1
1.4.25-1
1.4.25-2
1.4.28-1
1.4.29-1
1.4.29-2
1.4.29-3
1.4.31-1
1.4.31-2~bpo13+1
1.4.31-2
1.4.32-1
1.5.1-1
1.5.1-2
1.5.1-3
1.5.2-1
1.5.2-2
2.*
2.0.0-1
2.1.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-77643.json"

Debian:12 / xapian-core

Package

Name
xapian-core
Purl
pkg:deb/debian/xapian-core?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.4.22-1
1.4.25-1
1.4.25-2
1.4.28-1
1.4.29-1
1.4.29-2
1.4.29-3
1.4.31-1
1.4.31-2~bpo13+1
1.4.31-2
1.4.32-1
1.5.1-1
1.5.1-2
1.5.1-3
1.5.2-1
1.5.2-2
2.*
2.0.0-1
2.1.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-77643.json"

Debian:13 / xapian-core

Package

Name
xapian-core
Purl
pkg:deb/debian/xapian-core?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.4.29-3
1.4.31-1
1.4.31-2~bpo13+1
1.4.31-2
1.4.32-1
1.5.1-1
1.5.1-2
1.5.1-3
1.5.2-1
1.5.2-2
2.*
2.0.0-1
2.1.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-77643.json"

Debian:14 / xapian-core

Package

Name
xapian-core
Purl
pkg:deb/debian/xapian-core?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.32-1

Affected versions

1.*
1.4.29-3
1.4.31-1
1.4.31-2~bpo13+1
1.4.31-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-77643.json"