← Retour aux CVEs
CVE-2026-25136
HIGH8.1
Description
Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. A reflected Cross-site Scripting vulnerability was located in versions prior to 35.8.3, 38.5.4, and 39.3.1 in the rendering of the ExceptionMessage of the WebUI 500 error which could allow attackers to steal login session tokens of users who navigate to a specially crafted URL. Versions 35.8.3, 38.5.4, and 39.3.1 fix the issue.
Details CVE
Score CVSS v3.18.1
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurREQUIRED
Publie2/25/2026
Derniere modification2/27/2026
Sourcenvd
Observations honeypot0
Produits affectes
cern:rucio
Faiblesses (CWE)
CWE-79CWE-1004CWE-79
References
https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html(security-advisories@github.com)
https://github.com/rucio/rucio/releases/tag/35.8.3(security-advisories@github.com)
https://github.com/rucio/rucio/releases/tag/38.5.4(security-advisories@github.com)
https://github.com/rucio/rucio/releases/tag/39.3.1(security-advisories@github.com)
https://github.com/rucio/rucio/security/advisories/GHSA-h79m-5jjm-jm4q(security-advisories@github.com)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.