CVE-2025-54057Disclosure(apache / skywalking)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache skywalking systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache SkyWalking. This issue affects Apache SkyWalking: <= 10.2.0. Users are recommended to upgrade to version 10.3.0, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-80

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • skywalking

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-13); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
skywalking

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-13: 1Mentions · 2026-09-04: 1Patch / Workaround · 2026-09-04: 1Technical Details · 2026-04-13: 1Technical Details · 2026-09-04: 104-1309-04
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-131
Disclosure1
2026-09-041
Patch1
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Apache SkyWalking CVE-2025-54057: Stored XSS https://www.openwall.com/lists/oss-security/2026/04/13/3 CVE-2026-34476: SSRF via SW-URL Header in MCP Server https://www.openwall.com/lists/oss-security/2026/04/13/4 CVE-2026-34884: SSRF via set_skywalking_url Tool and GraphQL Expression Injection in MCP Server https://www.openwall.com/lists/oss-security/2026/04/13/5

    Post summary

    The text lists three newly disclosed CVEs in Apache SkyWalking with brief technical descriptions and links to discussion threads, but provides no PoC, exploit code, active exploitation claims, or patch details.

    00030437
    4.6K followersView on X
  • CyberSignal | Cybersecurity & AI News@XQOPTRX
    Patch

    🚨 [SECURITY FIX BYPASS] — APACHE DISCLOSES A NEW SKYwalking XSS AFTER THE PREVIOUS FIX FAILED TO FULLY CLOSE THE BUG CVE-2026-85229 affects Booster UI 10.2.0 → 10.4.0 and is explicitly described as an: INCOMPLETE FIX for an older vulnerability. CyberSignal Priority: 🟠 HIGH 🆔 CVE-2026-85229 🎯 Apache SkyWalking Booster UI 📦 Affected: 10.2.0 → 10.4.0 ✅ Fix: Horizon UI 1.0.0 🧩 Stored Cross-Site Scripting 📅 DISCLOSED: September 4, 2026 This is a security lesson that defenders see repeatedly: PATCHED does not always mean: FIXED. ### 🔎 What happened Apache disclosed CVE-2026-85229 today. The vulnerability affects: SKYWALKING BOOSTER UI and involves improper neutralization of attacker-controlled input during web-page generation. The result: STORED CROSS-SITE SCRIPTING. But the most interesting part is the vulnerability's relationship to: CVE-2025-54057. Apache describes today's flaw as: AN INCOMPLETE FIX OF THE PREVIOUS ISSUE. ### ⚔️ Attack chain Attacker-controlled content enters SkyWalking UI ↓ input is insufficiently neutralized ↓ payload stored in dashboard/widget content ↓ authorized user opens affected UI ↓ browser renders stored payload ↓ attacker-controlled JavaScript executes in trusted SkyWalking origin. Depending on the victim's session and browser context, XSS can potentially expose: session information application data authenticated actions UI manipulation. ### 🎯 What is affected Apache SkyWalking UI: 10.2.0 through 10.4.0. Apache recommends moving to: HORIZON UI 1.0.0. That version fixes the issue. ### 🔁 Why incomplete fixes matter A vulnerability fix often looks like: ATTACK INPUT ↓ SANITIZATION ADDED ↓ KNOWN PAYLOAD BLOCKED. But attackers and researchers then test: alternate encodings alternate fields alternate rendering paths alternate widgets alternate browser behavior. If the patch addressed: ONE EXPLOIT SHAPE instead of: THE ROOT TRUST BOUNDARY — the vulnerability returns. This is why patch validation matters as much as patch deployment. ### 🧠 Why this matters Observability platforms such as SkyWalking often contain: infrastructure topology service names application traces backend relationships performance data. They are frequently accessible by: developers SRE teams platform administrators. So stored browser-side attacks against monitoring platforms may run inside: HIGH-TRUST USER SESSIONS. The monitoring dashboard itself becomes: THE DELIVERY CHANNEL. ### ⚠️ Important caveat Apache does NOT currently provide evidence of: ACTIVE EXPLOITATION. There is also no CISA KEV entry identified in the current records. And the upstream CNA has not assigned a standard CVSS base score in the disclosure reviewed here. Therefore: DO NOT invent a severity score. The accurate description is: NEWLY DISCLOSED STORED XSS / INCOMPLETE SECURITY FIX. ### 🛡️ Defender action Organizations using SkyWalking should: → identify Booster UI 10.2.0–10.4.0 → migrate to Horizon UI 1.0.0 → inspect dashboard/widget content for unexpected markup → review privileged UI sessions → apply restrictive Content Security Policy where possible → avoid treating output encoding as the only defense → test the original CVE and bypass variants after upgrading. Security teams should always verify: PATCH INSTALLED and: ORIGINAL EXPLOIT + VARIANTS NO LONGER WORK. Those are not the same check. ### 🧠 CyberSignal insight The most dangerous phrase in vulnerability management may be: “WE ALREADY PATCHED THAT.” An incomplete fix gives defenders confidence— while leaving attackers: A DIFFERENT PATH THROUGH THE SAME DOOR. Sources: Apache Software Foundation · oss-security · CVE Program

    Post summary

    Apache SkyWalking Booster UI 10.2.0–10.4.0 is vulnerable to a stored XSS (CVE‑2026‑85229); the recommended fix is to upgrade to Horizon UI 1.0.0 and apply mitigations such as CSP.

    01010125
    196 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheskywalking---

Explore more