Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-25136

Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
Back to all
CVE

CVE-2026-25136

Rucio WebUI has a Reflected Cross-site Scripting Vulnerability

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. A reflected Cross-site Scripting vulnerability was located in versions prior to 35.8.3, 38.5.4, and 39.3.1 in the rendering of the ExceptionMessage of the WebUI 500 error which could allow attackers to steal login session tokens of users who navigate to a specially crafted URL. Versions 35.8.3, 38.5.4, and 39.3.1 fix the issue.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
8.1
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
C
H
U
-

Related Resources

No items found.

References

https://cheatsheetseries.owasp.org/cheatsheets/CrossSiteScriptingPreventionCheat_Sheet.html, https://github.com/rucio/rucio/releases/tag/35.8.3, https://github.com/rucio/rucio/releases/tag/38.5.4, https://github.com/rucio/rucio/releases/tag/39.3.1, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25136.json, https://github.com/rucio/rucio/security/advisories/GHSA-h79m-5jjm-jm4q, https://nvd.nist.gov/vuln/detail/CVE-2026-25136

Severity

8.1

CVSS Score
0
10

Basic Information

Base CVSS
8.1
EPSS Probability
0.0008%
EPSS Percentile
0.23426%
Introduced Version
0,d98ebf29b58b30f07e1607d0245ac63006aeb634,000ea9fcba4980681d74af76ef355e0946fbbcc8
Fix Available
ba9203702629af7bb1f95d5cf9ba8fcf1f943105,c851ad216e0e0e3d50405eab3331dfe21c96ddd3,ba2a7e66b1e3c73b5cf9e0000e6621e8dc45bfe7

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading