---
id: CVE-2026-77643
title: >-
  A cross-site scripting vulnerability in 

  queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and
  before 1.4.32 exists due to incomplete HTML escaping by
  Xapian::MSet::snippet()
summary: >-
  A cross-site scripting vulnerability in 

  queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and
  before 1.4.32 exists due to incomplete HTML escaping by
  Xapian::MSet::snippet(). NOTE: this issue exists because of a m…
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-08-20'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T16:04:24.933'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77643'
references:
  - url: 'https://bugs.debian.org/1144490'
    label: cve@mitre.org
  - url: 'https://lists.xapian.org/pipermail/xapian-devel/2026-August/003429.html'
    label: cve@mitre.org
  - url: 'https://trac.xapian.org/wiki/SecurityFixes/2018-07-02#a2026-08-13update'
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00156
epssPercentile: 0.05202
ingestedAt: '2026-09-09T16:14:05.514Z'
---

## Overview

A cross-site scripting vulnerability in 
queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
