https://seclists.org/oss-sec/2026/q3/648: CVE-2026-85229: Apache SkyWalking: CWE-79 stod XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)
Published Sep 4, 2026
·Updated
Affected Software
1 affected component
Apache SkyWalking>=10.2.0<=10.4.0
Frequently Asked Questions
1
Which deployments are affected?
Apache SkyWalking UI versions 10.2.0 through 10.4.0 are affected. The issue is specifically in Booster UI dashboard widgets.
2
What should teams upgrade to?
Users are recommended to upgrade to Horizon UI 1.0.0, which fixes the issue.