MEDIUMGo

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability

CVE-2026-25688Published 1 month agoUpdated 6 days agoSource: OSV

Affected packages

  • github.com/apache/incubator-answer

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.41%
EPSS percentile
33.4%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 33%.

Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability | HackTribune