Unrated severityNVD Advisory· Published Sep 4, 2026
Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)
CVE-2026-85229
Description
UNSUPPORTED WHEN ASSIGNED Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Booster UI.
This issue affects Apache SkyWalking UI : from 10.2.0 through 10.4.0.
Users are recommended to upgrade to Horizon UI 1.0.0, which fixes the issue.
Affected products
2- Range: from 10.2.0 through 10.4.0
- Range: from 10.2.0 through 10.4.0
Patches
Vulnerability mechanics
References
1- lists.apache.org/thread/oswo0kxr7g2jgdoz3wd923nslo36jsv8mitrevendor-advisory
News mentions
0No linked articles in our index yet.