{"id":"AZL-96924","summary":"CVE-2026-77643 affecting package xapian-core 1.4.26-2","details":"A cross-site scripting vulnerability in \nqueryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499.","modified":"2026-09-20T05:32:18Z","published":"2026-08-20T22:18:06Z","upstream":["CVE-2026-77643"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77643"}],"affected":[{"package":{"name":"xapian-core","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/xapian-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.4.26-2"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96924.json"}}],"schema_version":"1.9.0"}