CVE-2026-73237: Apache Allura: XSS in markdown pipeline
Published Aug 12, 2026
·Updated
XSS vulnerability in Markdown handling in Apache Allura.
This issue affects Apache Allura: from 1.10.0 before 1.19.1.
Users are recommended to upgrade to version 1.19.1, which fixes the issue.
Affected Software
1 affected component
Apache Allura>=1.10.0<1.19.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Allurato a version that resolves this vulnerability.Fixed in 1.19.1
Event History
Aug 12, 2026
CVE Published
via MITRE·04:42 PM
Data Sourced
via MITRE·04:42 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-73237?
CVE-2026-73237 has a risk level of 32.
2
How do I fix CVE-2026-73237?
To fix CVE-2026-73237, upgrade Apache Allura to version 1.19.1 or later.
3
What does CVE-2026-73237 affect?
CVE-2026-73237 affects the Markdown handling in Apache Allura versions from 1.10.0 to before 1.19.1.
4
What type of vulnerability is CVE-2026-73237?
CVE-2026-73237 is classified as a Cross-Site Scripting (XSS) vulnerability.
5
When was CVE-2026-73237 published?
CVE-2026-73237 was published on August 12, 2026.