<Vulnerability name="CVE-2026-77643">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-08-20T21:23:31</PublicDate>
    <Bugzilla id="2520814" url="https://bugzilla.redhat.com/show_bug.cgi?id=2520814" xml:lang="en:us">
xapian-core: Xapian xapian-core: Arbitrary code execution via incomplete HTML escaping
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>4.4</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-79</CWE>
    <Details xml:lang="en:us" source="Mitre">
A cross-site scripting vulnerability in 
queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Xapian xapian-core. This cross-site scripting (XSS) vulnerability is due to incomplete HTML escaping by the Xapian::MSet::snippet() function. A remote attacker could exploit this by injecting malicious script, leading to arbitrary code execution in the user's browser context. This could result in information disclosure or session hijacking.
    </Details>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>xapian-core</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>xapian-core</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>xapian-core</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-77643
https://nvd.nist.gov/vuln/detail/CVE-2026-77643
https://bugs.debian.org/1144490
https://lists.xapian.org/pipermail/xapian-devel/2026-August/003429.html
https://trac.xapian.org/wiki/SecurityFixes/2018-07-02#a2026-08-13update
    </References>
</Vulnerability>