CVE-2026-77643: XSS
Published Aug 20, 2026
·Updated
A cross-site scripting vulnerability in queryparser/termgeneratorinternal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499.
Affected Software
1 affected component
Xapian xapian-core<2.1.0, <1.4.32
Event History
Aug 20, 2026
CVE Published
via MITRE·09:23 PM
Data Sourced
via MITRE·09:23 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which versions are affected?
Affected releases are xapian-core versions before 2.1.0 and versions before 1.4.32. Upgrade to 2.1.0 or 1.4.32, as applicable to the release branch you use.
2
What are the exploitation prerequisites?
The CVSS vector indicates network reachability, high attack complexity, low privileges required, and required user interaction. Successful exploitation can affect confidentiality and integrity across a changed security scope.