VYPR
Unrated severityNVD Advisory· Published Sep 4, 2026

Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)

CVE-2026-85229

Description

UNSUPPORTED WHEN ASSIGNED  Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Booster UI.

This issue affects Apache SkyWalking UI : from 10.2.0 through 10.4.0.

Users are recommended to upgrade to Horizon UI 1.0.0, which fixes the issue.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.