CVE-2026-77643

medium

Description

A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499.

References

https://trac.xapian.org/wiki/SecurityFixes/2018-07-02#a2026-08-13update

https://lists.xapian.org/pipermail/xapian-devel/2026-August/003429.html

https://bugs.debian.org/1144490

Details

Source: Mitre, NVD

Published: 2026-08-20

Updated: 2026-08-20

Risk Information

CVSS v2

Base Score: 3.6

Vector: CVSS2#AV:N/AC:H/Au:S/C:P/I:P/A:N

Severity: Low

CVSS v3

Base Score: 4.4

Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N

Severity: Medium