{
  "from_raw": "Sheng Wu <wusheng@apache.org>",
  "from": "Sheng Wu <wu...@apache.org>",
  "gravatar": "496661e395bd17ea046bd2214b02992c",
  "to": "an...@apache.org,\n de...@skywalking.apache.org",
  "subject": "CVE-2026-85229: Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)",
  "message-id": "<86a10b14-14a1-e18a-0073-ebc1ac22c2bd@apache.org>",
  "mid": "byj0zyogy2nyo28rg36bk18f8fnffknv",
  "permalinks": [
    "byj0zyogy2nyo28rg36bk18f8fnffknv",
    "r8cc54e324756b451d4ab8e5a2ecbcc92004bbf633f076550a418449f@<announce.apache.org>"
  ],
  "dbid": "88ba86df3de4591daa0461b8835e3d32ad47320775cc1b7d7cc57682b4664208",
  "cc": "de...@skywalking.apache.org",
  "epoch": 1788480342,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/09/04 00:05:42",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Affected versions:\n\n- Apache SkyWalking 10.2.0 through 10.4.0\n\nDescription:\n\nImproper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Booster UI.\n\n\n\nThis issue affects Apache SkyWalking UI : from 10.2.0 through 10.4.0.\n\n\n\nUsers are recommended to upgrade to version Horizon UI 1.0.0, which fixes the issue.\n\nCredit:\n\nn0mi1k (reporter)\n\nReferences:\n\nhttps://skywalking.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-85229\n\n",
  "body_short": "Affected versions:\n\n- Apache SkyWalking 10.2.0 through 10.4.0\n\nDescription:\n\nImproper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Boos",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 3147,
  "id": "byj0zyogy2nyo28rg36bk18f8fnffknv"
}