Cross-Site Scripting Vulnerability in Apache SkyWalking UI
CVE-2026-85229

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
4 September 2026

What is CVE-2026-85229?

The Apache SkyWalking UI versions 10.2.0 through 10.4.0 contain a vulnerability that allows for improper neutralization of input during web page generation, leading to cross-site scripting (XSS) issues. This can allow attackers to execute arbitrary scripts in the context of the user's browser. Users are strongly advised to upgrade to Horizon UI 1.0.0, which effectively addresses this security flaw.

Affected Version(s)

Apache SkyWalking 10.2.0 <= 10.4.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0mi1k
.