- Package:
- libxapian30
- Source:
- libxapian30
- Description:
- Search engine library
- Submitter:
- Olly Betts
- Date:
- 2026-08-31 17:33:03 UTC
- Severity:
- normal
- Tags:
This was reported to upstream's public development list: https://lists.xapian.org/pipermail/xapian-devel/2026-August/003429.html The bug is missing HTML escaping, potentially allowing an attacker to inject unescaped data into generated HTML search results. It's effectively a corner case missed when we fixed CVE-2018-0499. It affects upstream releases 1.4.x for x <= 31 and 2.0.0. Upstream releases 1.4.32 and 2.0.1 include a fix, and I've already uploaded 1.4.32 to unstable and 2.0.1 to experimental. There are patches here: https://trac.xapian.org/wiki/SecurityFixes/2018-07-02#a2026-08-13update The actually fix is just this (the patches also add test coverage): if (hi_start.empty() && hi_end.empty() && text.size() <= length) { - // Too easy! - return text; + // The text is already short enough so we just need to perform + // escaping. + string output; + append_escaping_xml(text.data(), text.data() + text.size(), output); + return output; } The 4 variables in the condition are all parameters from the MSet::snippet() API call. In order to be exploited, hi_start and hi_end need to be passed as empty strings (they have default values which aren't empty). I'd expect most usage in a web context would want to highlight matching terms in the snippet and so it's probably uncommon to pass empty string here - I looked for an example of such usage with codesearch.d.n but didn't find anything. However empty highlighting strings are a legitimate way to call this method, and I may have missed an instance, or such use may be present in code that hasn't been packaged for Debian. Therefore I think we should apply this patch to stable. I've already contacted the security team and they said we should handle this via a stable update. Cheers, Olly
Hi Olly, FTR, I requested a CVE for this issue so we can properly track it as separate CVE id. Regards, Salvatore
Control: retitle -1 libxapian30: CVE-2026-77643: previously missed corner case of CVE-2018-0499 This got CVE-2026-77643 assigned. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
xapian-core, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1144490@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Olly Betts <olly@survex.com> (supplier of updated xapian-core package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 16 Aug 2026 09:59:21 +1200
Source: xapian-core
Architecture: source
Version: 1.4.29-3+deb13u1
Distribution: trixie
Urgency: medium
Maintainer: Olly Betts <olly@survex.com>
Changed-By: Olly Betts <olly@survex.com>
Closes: 1144490
Changes:
xapian-core (1.4.29-3+deb13u1) trixie; urgency=medium
.
* Cherry-pick fix for missed corner case of CVE-2018-0499. New patch:
cve-2018-0499-mset-snippet-escaping-no-highlighting-1.4.x.patch
(Closes: #1144490)
Checksums-Sha1:
d55887c43f638a3695acae2d1b03fd3f3584ee4a 2170 xapian-core_1.4.29-3+deb13u1.dsc
3d4f92359d5aa31eb75b2512c5f4fd728a46bb34 21188 xapian-core_1.4.29-3+deb13u1.debian.tar.xz
5d5a2afab491ec63837fcf825bd55f8970ca3754 8185 xapian-core_1.4.29-3+deb13u1_amd64.buildinfo
Checksums-Sha256:
a8ce3f460f0174c243afaadbed7a8fde835ff1bf96813a9685ebe12d3350eaa0 2170 xapian-core_1.4.29-3+deb13u1.dsc
de94df438d212e40bb96ecac3032a9c8ef2fcf173fd0d9ad5a69b83c84143ee2 21188 xapian-core_1.4.29-3+deb13u1.debian.tar.xz
cc44cd021096c213571f083794498d7729521a0ec970ab56f76bce29a152f1bc 8185 xapian-core_1.4.29-3+deb13u1_amd64.buildinfo
Files:
c3d5088c80cce7f38247d9ed095dd337 2170 libs optional xapian-core_1.4.29-3+deb13u1.dsc
952d2b30f69f0d3f6b45d68cec0270c0 21188 libs optional xapian-core_1.4.29-3+deb13u1.debian.tar.xz
2b30373171908b423079cc95a0e6ed41 8185 libs optional xapian-core_1.4.29-3+deb13u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEECOJAD/f+j+3jrLUoGBR7BzutKwcFAmqA5TUACgkQGBR7Bzut
KwcHgg/8CcA0xg/UrNdziNdqHM8V1DwOHoQIP63vXLIp93DyZcW+/Q6ZPuxFInhI
GhK3Dknlg2skjm83Nh2VDJbDb6Jb4Ufyh31KavS3umMV8ap9bsQuyi8YrLGk7QoB
9SpPYhGaKE4G+I6z9FWx2TkjVbQc1UkBhWO7//tvNdLuTuoBMwuChXXAEqsF8Tqg
d/9umaPvhPNEwc1H1GGBhlquQrl/7736vHWMRA4OjfwfDTEbc/AuugwkCK/jV+4k
m8K/6i1wu2at9s9Q4J4GnhMJIxW0VD8RZn+0Dtha572CC/fBWcBwhCK818AybrPL
aISf6PUgGpTUTLPbNV2CYT7pYpyCOlpYdmeuyzK37YPjNtAzTJg7NndjH5HyqNXX
nCp/f2A7ZYCLHLrbMgI1mHLapKyNXmPKJArP3a6pIHumhpKs3CWr5FMK5EpkObg+
YlUM8QNnzhPQTQ1jxTHi9QXxnhNr48d5eVgqNHfMhNc6EpS/EL2DHg0JDH6VC3KP
Hzvrmgi5HIzltY1XGMLW3faiXjHnh192MLC+ssT6+OO1yBCuFNsN2A43fd7CszIl
EH7n0nRwv6dVkolyPc0ppHihLrCkx1bXdk61t3+2/Pqm/q8QImdlaGTUwyAZt1KQ
pHMTMbcWy4kr38+/1tIIF65BFH2ph5dh+fyNsWswrHRtgi0on10=
=183y
-----END PGP SIGNATURE-----