THREAT OPS › Threat News › CVE-2026-85229: Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)
CVE-2026-85229: Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)
<p>Posted by Sheng Wu on Sep 03</p>Affected versions:<br /> <br /> - Apache SkyWalking 10.2.0 through 10.4.0<br /> <br /> Description:<br /> <br /> Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking <br /> Booster UI.<br /> <br /> This issue affects Apache SkyWalking UI : from 10.2.0 through 10.4.0.<br /> <br /> Users a
Indicators of compromise
- CVE-2026-85229cve
- CVE-2025-54057cve
- https://skywalking.apache.org/url
Original source: https://seclists.org/oss-sec/2026/q3/648