Junglewise Threat Intelligence

CVE-2026-73238: Apache Allura XSS in code display

CVE-2026-73238 · Severity: medium · CVSS 6.1 · Published 2026-08-12

Technologies: Apache Allura. Vendors: Apache.

Executive brief

Apache Allura is an open-source project hosting and collaboration platform used by development teams. A cross-site scripting (XSS) vulnerability in the code display feature allows attackers to inject malicious scripts that could execute in users' browsers when viewing code, potentially stealing session tokens or performing unauthorized actions on behalf of users.

Technical details

This is a cross-site scripting (XSS) vulnerability in the code display component of Apache Allura. The vulnerability allows injection of malicious JavaScript that executes in the context of a user's browser when viewing code repositories or files. The attack vector is network-based and does not require authentication to trigger in typical XSS scenarios. An attacker can exploit this to steal session cookies, perform actions on behalf of logged-in users, or redirect users to malicious sites. The vulnerability affects Apache Allura before version 1.19.1, which contains the fix.

Affected products

  • Apache Allura before 1.19.1

Timeline

  • 2026-06-29: disclosed
  • 2026-06-29: patched: Fixed in version 1.19.1

References

Related threats