CVE-2026-73238: Apache Allura: XSS in code display
Published Aug 12, 2026
·Updated
XSS vulnerability in code display in Apache Allura.
This issue affects Apache Allura: before 1.19.1.
Users are recommended to upgrade to version 1.19.1, which fixes the issue.
Affected Software
1 affected component
Apache Allura<1.19.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Allurato a version that resolves this vulnerability.Fixed in 1.19.1
Event History
Aug 12, 2026
CVE Published
via MITRE·04:41 PM
Data Sourced
via MITRE·04:41 PM
DescriptionWeakness
Frequently Asked Questions
1
When was CVE-2026-73238 published?
CVE-2026-73238 was published on August 12, 2026.