rucio-webui
Rucio WebUI package
Activity
- Latest release
- 6d ago
- Total releases
- 486
- Cadence
- ~6 days
- Last 12 months
- 46
Details
- License
- Apache-2.0
- First release
- May 10, 2016
| Version | Released | |
|---|---|---|
41.2.2
patch
| ||
38.6.2
patch
| ||
41.2.1
patch
| ||
35.9.2
patch
| ||
41.2.0
minor
| ||
35.9.1.post2
pre
| ||
35.9.1.post1
pre
| ||
35.9.1
patch
| ||
40.4.2
patch
| ||
38.6.1
patch
| ||
41.1.1
patch
| ||
41.1.0
minor
| ||
41.0.0
major
| ||
38.6.0
minor
| ||
35.9.0
minor
| ||
41.0.0rc1
pre
| ||
40.4.1
patch
| ||
40.4.0
minor
| ||
40.3.0
minor
| ||
40.2.0
minor
| ||
40.1.2
patch
| ||
35.8.5
patch
| ||
38.5.5
patch
| ||
39.4.2
patch
| ||
40.1.1
patch
| ||
40.0.0
major
| ||
40.1.0
minor
| ||
40.0.0rc1
pre
| ||
39.4.1
patch
| ||
35.8.4
patch
| ||
39.4.0
minor
| ||
35.8.3
patch
| ||
38.5.4
patch
| ||
39.3.1
patch
| ||
38.5.3
patch
6 CVEs
CVE-2026-25736
PYSEC-2026-3055
GHSA-fq4f-4738-rqxm
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom RSE Attribute of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA stored XSS payload can be introduced via a custom RSE attribute value and is later rendered when the RSE is viewed. Create Path: Trigger Path: Request
Response
Storing XSS Payload in RSE Attribute XSS Payload triggering when viewing RSEImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25735
PYSEC-2026-3054
GHSA-8wpv-6x3f-3rm5
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Identity Name of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsThe identity name is stored and later rendered without output encoding. Create Path: Trigger Path: Request
Response
Storing XSS payload in account identity name Triggering XSS payload when viewing account ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
References
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25734
PYSEC-2026-3057
GHSA-h9fp-p2p9-873q
Jul 13, 2026
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the RSE metadata of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsSeveral metadata fields accept arbitrary input which is stored and later rendered unsafely in the WebUI when the RSEs are listed in the RSE Management dashboard. Create Path: Trigger Paths: Vulnerable Attributes: Request
Response
Stored XSS payload triggering in RSE listing after adding XSS payload in metadata ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25733
PYSEC-2026-3058
GHSA-rwj9-7j48-9f7q
Jul 13, 2026
Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom Rules function of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA malicious payload supplied in the Create Path: Trigger Paths:
Create Request
Response
Creating RSE with XSS payload in comment Reviewing rule creation requests XSS Payload triggering on rule review ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25138
PYSEC-2026-3053
GHSA-38wq-6q2w-hcf9
Jul 13, 2026
Rucio WebUI has Username Enumeration via Login Error Message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThe WebUI login endpoint returns distinct error messages depending on whether a supplied username exists, allowing unauthenticated attackers to enumerate valid usernames. DetailsWhen submitting invalid credentials to This behavioral difference allows an attacker to distinguish valid usernames from invalid ones by observing the response content. Proof of ConceptBogus Login (Non-existent Username "15251087")
Bogus Login (Existing Username "root", Wrong Password)
The difference in error messages confirms whether a username exists. ImpactAn unauthenticated attacker can enumerate valid usernames, which may be leveraged for targeted password guessing, credential stuffing, or social engineering attacks. Remediation / MitigationReturn a generic authentication failure message for all login errors, regardless of whether the username exists. Avoid disclosing account or identity existence through error responses. Consider implementing rate limiting or additional login throttling to further reduce abuse. Reources:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25136
PYSEC-2026-3056
GHSA-h79m-5jjm-jm4q
Jul 13, 2026
Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
SummaryA reflected Cross-site Scripting vulnerability was located in the rendering of the ExceptionMessage of the WebUI 500 error which could allow attackers to steal login session tokens of users who navigate to a specially crafted URL. DetailsThe WebUI error message renders PoC
Server response (excerpt):
XSS payload triggering (Displaying session token) when browsing to crafted URL When the WebUI inserts
XSS payload triggering (Displaying session token) on error when creating account key Server response (excerpt) contains ImpactAny authenticated WebUI user who follows a crafted link or triggers a request containing attacker-controlled input in a field that causes an error may execute arbitrary JavaScript in the WebUI origin. This vulnerability is more impactful due to the lack of protection of cookies (The Session token does not have HttpOnly attribute) and lack of Content Security Policy that would prevent thrid-party scripts from loading. Attackers can steal session cookies/tokens or perform actions as the victim like creating a new UserPass identity with an attacker known password. Example URL to Create UserPass for Root
Account Payload to Create UserPass
Creating identity for Root account via reflected XSS All WebUI users are impacted. Remediation / MitigationChange all client-side insertions of server-provided text from Additionally, consider adding a Content Security Policy (CSP) to mitigate external script execution and set the HTTPOnly flag for session cookies. Also, the API token should not be set in a JavaScript variable as it can be accessed by an attacker even with the HTTPOnly flag set on the session cookie.
References:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
39.3.0
minor
6 CVEs
CVE-2026-25736
PYSEC-2026-3055
GHSA-fq4f-4738-rqxm
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom RSE Attribute of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA stored XSS payload can be introduced via a custom RSE attribute value and is later rendered when the RSE is viewed. Create Path: Trigger Path: Request
Response
Storing XSS Payload in RSE Attribute XSS Payload triggering when viewing RSEImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25735
PYSEC-2026-3054
GHSA-8wpv-6x3f-3rm5
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Identity Name of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsThe identity name is stored and later rendered without output encoding. Create Path: Trigger Path: Request
Response
Storing XSS payload in account identity name Triggering XSS payload when viewing account ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
References
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25734
PYSEC-2026-3057
GHSA-h9fp-p2p9-873q
Jul 13, 2026
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the RSE metadata of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsSeveral metadata fields accept arbitrary input which is stored and later rendered unsafely in the WebUI when the RSEs are listed in the RSE Management dashboard. Create Path: Trigger Paths: Vulnerable Attributes: Request
Response
Stored XSS payload triggering in RSE listing after adding XSS payload in metadata ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25733
PYSEC-2026-3058
GHSA-rwj9-7j48-9f7q
Jul 13, 2026
Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom Rules function of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA malicious payload supplied in the Create Path: Trigger Paths:
Create Request
Response
Creating RSE with XSS payload in comment Reviewing rule creation requests XSS Payload triggering on rule review ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25138
PYSEC-2026-3053
GHSA-38wq-6q2w-hcf9
Jul 13, 2026
Rucio WebUI has Username Enumeration via Login Error Message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThe WebUI login endpoint returns distinct error messages depending on whether a supplied username exists, allowing unauthenticated attackers to enumerate valid usernames. DetailsWhen submitting invalid credentials to This behavioral difference allows an attacker to distinguish valid usernames from invalid ones by observing the response content. Proof of ConceptBogus Login (Non-existent Username "15251087")
Bogus Login (Existing Username "root", Wrong Password)
The difference in error messages confirms whether a username exists. ImpactAn unauthenticated attacker can enumerate valid usernames, which may be leveraged for targeted password guessing, credential stuffing, or social engineering attacks. Remediation / MitigationReturn a generic authentication failure message for all login errors, regardless of whether the username exists. Avoid disclosing account or identity existence through error responses. Consider implementing rate limiting or additional login throttling to further reduce abuse. Reources:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25136
PYSEC-2026-3056
GHSA-h79m-5jjm-jm4q
Jul 13, 2026
Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
SummaryA reflected Cross-site Scripting vulnerability was located in the rendering of the ExceptionMessage of the WebUI 500 error which could allow attackers to steal login session tokens of users who navigate to a specially crafted URL. DetailsThe WebUI error message renders PoC
Server response (excerpt):
XSS payload triggering (Displaying session token) when browsing to crafted URL When the WebUI inserts
XSS payload triggering (Displaying session token) on error when creating account key Server response (excerpt) contains ImpactAny authenticated WebUI user who follows a crafted link or triggers a request containing attacker-controlled input in a field that causes an error may execute arbitrary JavaScript in the WebUI origin. This vulnerability is more impactful due to the lack of protection of cookies (The Session token does not have HttpOnly attribute) and lack of Content Security Policy that would prevent thrid-party scripts from loading. Attackers can steal session cookies/tokens or perform actions as the victim like creating a new UserPass identity with an attacker known password. Example URL to Create UserPass for Root
Account Payload to Create UserPass
Creating identity for Root account via reflected XSS All WebUI users are impacted. Remediation / MitigationChange all client-side insertions of server-provided text from Additionally, consider adding a Content Security Policy (CSP) to mitigate external script execution and set the HTTPOnly flag for session cookies. Also, the API token should not be set in a JavaScript variable as it can be accessed by an attacker even with the HTTPOnly flag set on the session cookie.
References:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
38.5.2
patch
6 CVEs
CVE-2026-25736
PYSEC-2026-3055
GHSA-fq4f-4738-rqxm
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom RSE Attribute of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA stored XSS payload can be introduced via a custom RSE attribute value and is later rendered when the RSE is viewed. Create Path: Trigger Path: Request
Response
Storing XSS Payload in RSE Attribute XSS Payload triggering when viewing RSEImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25735
PYSEC-2026-3054
GHSA-8wpv-6x3f-3rm5
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Identity Name of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsThe identity name is stored and later rendered without output encoding. Create Path: Trigger Path: Request
Response
Storing XSS payload in account identity name Triggering XSS payload when viewing account ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
References
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25734
PYSEC-2026-3057
GHSA-h9fp-p2p9-873q
Jul 13, 2026
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the RSE metadata of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsSeveral metadata fields accept arbitrary input which is stored and later rendered unsafely in the WebUI when the RSEs are listed in the RSE Management dashboard. Create Path: Trigger Paths: Vulnerable Attributes: Request
Response
Stored XSS payload triggering in RSE listing after adding XSS payload in metadata ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25733
PYSEC-2026-3058
GHSA-rwj9-7j48-9f7q
Jul 13, 2026
Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom Rules function of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA malicious payload supplied in the Create Path: Trigger Paths:
Create Request
Response
Creating RSE with XSS payload in comment Reviewing rule creation requests XSS Payload triggering on rule review ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25138
PYSEC-2026-3053
GHSA-38wq-6q2w-hcf9
Jul 13, 2026
Rucio WebUI has Username Enumeration via Login Error Message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThe WebUI login endpoint returns distinct error messages depending on whether a supplied username exists, allowing unauthenticated attackers to enumerate valid usernames. DetailsWhen submitting invalid credentials to This behavioral difference allows an attacker to distinguish valid usernames from invalid ones by observing the response content. Proof of ConceptBogus Login (Non-existent Username "15251087")
Bogus Login (Existing Username "root", Wrong Password)
The difference in error messages confirms whether a username exists. ImpactAn unauthenticated attacker can enumerate valid usernames, which may be leveraged for targeted password guessing, credential stuffing, or social engineering attacks. Remediation / MitigationReturn a generic authentication failure message for all login errors, regardless of whether the username exists. Avoid disclosing account or identity existence through error responses. Consider implementing rate limiting or additional login throttling to further reduce abuse. Reources:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25136
PYSEC-2026-3056
GHSA-h79m-5jjm-jm4q
Jul 13, 2026
Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
SummaryA reflected Cross-site Scripting vulnerability was located in the rendering of the ExceptionMessage of the WebUI 500 error which could allow attackers to steal login session tokens of users who navigate to a specially crafted URL. DetailsThe WebUI error message renders PoC
Server response (excerpt):
XSS payload triggering (Displaying session token) when browsing to crafted URL When the WebUI inserts
XSS payload triggering (Displaying session token) on error when creating account key Server response (excerpt) contains ImpactAny authenticated WebUI user who follows a crafted link or triggers a request containing attacker-controlled input in a field that causes an error may execute arbitrary JavaScript in the WebUI origin. This vulnerability is more impactful due to the lack of protection of cookies (The Session token does not have HttpOnly attribute) and lack of Content Security Policy that would prevent thrid-party scripts from loading. Attackers can steal session cookies/tokens or perform actions as the victim like creating a new UserPass identity with an attacker known password. Example URL to Create UserPass for Root
Account Payload to Create UserPass
Creating identity for Root account via reflected XSS All WebUI users are impacted. Remediation / MitigationChange all client-side insertions of server-provided text from Additionally, consider adding a Content Security Policy (CSP) to mitigate external script execution and set the HTTPOnly flag for session cookies. Also, the API token should not be set in a JavaScript variable as it can be accessed by an attacker even with the HTTPOnly flag set on the session cookie.
References:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
39.2.0
minor
6 CVEs
CVE-2026-25736
PYSEC-2026-3055
GHSA-fq4f-4738-rqxm
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom RSE Attribute of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA stored XSS payload can be introduced via a custom RSE attribute value and is later rendered when the RSE is viewed. Create Path: Trigger Path: Request
Response
Storing XSS Payload in RSE Attribute XSS Payload triggering when viewing RSEImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25735
PYSEC-2026-3054
GHSA-8wpv-6x3f-3rm5
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Identity Name of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsThe identity name is stored and later rendered without output encoding. Create Path: Trigger Path: Request
Response
Storing XSS payload in account identity name Triggering XSS payload when viewing account ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
References
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25734
PYSEC-2026-3057
GHSA-h9fp-p2p9-873q
Jul 13, 2026
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the RSE metadata of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsSeveral metadata fields accept arbitrary input which is stored and later rendered unsafely in the WebUI when the RSEs are listed in the RSE Management dashboard. Create Path: Trigger Paths: Vulnerable Attributes: Request
Response
Stored XSS payload triggering in RSE listing after adding XSS payload in metadata ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25733
PYSEC-2026-3058
GHSA-rwj9-7j48-9f7q
Jul 13, 2026
Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom Rules function of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA malicious payload supplied in the Create Path: Trigger Paths:
Create Request
Response
Creating RSE with XSS payload in comment Reviewing rule creation requests XSS Payload triggering on rule review ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25138
PYSEC-2026-3053
GHSA-38wq-6q2w-hcf9
Jul 13, 2026
Rucio WebUI has Username Enumeration via Login Error Message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThe WebUI login endpoint returns distinct error messages depending on whether a supplied username exists, allowing unauthenticated attackers to enumerate valid usernames. DetailsWhen submitting invalid credentials to This behavioral difference allows an attacker to distinguish valid usernames from invalid ones by observing the response content. Proof of ConceptBogus Login (Non-existent Username "15251087")
Bogus Login (Existing Username "root", Wrong Password)
The difference in error messages confirms whether a username exists. ImpactAn unauthenticated attacker can enumerate valid usernames, which may be leveraged for targeted password guessing, credential stuffing, or social engineering attacks. Remediation / MitigationReturn a generic authentication failure message for all login errors, regardless of whether the username exists. Avoid disclosing account or identity existence through error responses. Consider implementing rate limiting or additional login throttling to further reduce abuse. Reources:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25136
PYSEC-2026-3056
GHSA-h79m-5jjm-jm4q
Jul 13, 2026
Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
SummaryA reflected Cross-site Scripting vulnerability was located in the rendering of the ExceptionMessage of the WebUI 500 error which could allow attackers to steal login session tokens of users who navigate to a specially crafted URL. DetailsThe WebUI error message renders PoC
Server response (excerpt):
XSS payload triggering (Displaying session token) when browsing to crafted URL When the WebUI inserts
XSS payload triggering (Displaying session token) on error when creating account key Server response (excerpt) contains ImpactAny authenticated WebUI user who follows a crafted link or triggers a request containing attacker-controlled input in a field that causes an error may execute arbitrary JavaScript in the WebUI origin. This vulnerability is more impactful due to the lack of protection of cookies (The Session token does not have HttpOnly attribute) and lack of Content Security Policy that would prevent thrid-party scripts from loading. Attackers can steal session cookies/tokens or perform actions as the victim like creating a new UserPass identity with an attacker known password. Example URL to Create UserPass for Root
Account Payload to Create UserPass
Creating identity for Root account via reflected XSS All WebUI users are impacted. Remediation / MitigationChange all client-side insertions of server-provided text from Additionally, consider adding a Content Security Policy (CSP) to mitigate external script execution and set the HTTPOnly flag for session cookies. Also, the API token should not be set in a JavaScript variable as it can be accessed by an attacker even with the HTTPOnly flag set on the session cookie.
References:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
39.1.0
minor
6 CVEs
CVE-2026-25736
PYSEC-2026-3055
GHSA-fq4f-4738-rqxm
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom RSE Attribute of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA stored XSS payload can be introduced via a custom RSE attribute value and is later rendered when the RSE is viewed. Create Path: Trigger Path: Request
Response
Storing XSS Payload in RSE Attribute XSS Payload triggering when viewing RSEImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25735
PYSEC-2026-3054
GHSA-8wpv-6x3f-3rm5
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Identity Name of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsThe identity name is stored and later rendered without output encoding. Create Path: Trigger Path: Request
Response
Storing XSS payload in account identity name Triggering XSS payload when viewing account ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
References
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25734
PYSEC-2026-3057
GHSA-h9fp-p2p9-873q
Jul 13, 2026
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the RSE metadata of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsSeveral metadata fields accept arbitrary input which is stored and later rendered unsafely in the WebUI when the RSEs are listed in the RSE Management dashboard. Create Path: Trigger Paths: Vulnerable Attributes: Request
Response
Stored XSS payload triggering in RSE listing after adding XSS payload in metadata ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25733
PYSEC-2026-3058
GHSA-rwj9-7j48-9f7q
Jul 13, 2026
Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom Rules function of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA malicious payload supplied in the Create Path: Trigger Paths:
Create Request
Response
Creating RSE with XSS payload in comment Reviewing rule creation requests XSS Payload triggering on rule review ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25138
PYSEC-2026-3053
GHSA-38wq-6q2w-hcf9
Jul 13, 2026
Rucio WebUI has Username Enumeration via Login Error Message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThe WebUI login endpoint returns distinct error messages depending on whether a supplied username exists, allowing unauthenticated attackers to enumerate valid usernames. DetailsWhen submitting invalid credentials to This behavioral difference allows an attacker to distinguish valid usernames from invalid ones by observing the response content. Proof of ConceptBogus Login (Non-existent Username "15251087")
Bogus Login (Existing Username "root", Wrong Password)
The difference in error messages confirms whether a username exists. ImpactAn unauthenticated attacker can enumerate valid usernames, which may be leveraged for targeted password guessing, credential stuffing, or social engineering attacks. Remediation / MitigationReturn a generic authentication failure message for all login errors, regardless of whether the username exists. Avoid disclosing account or identity existence through error responses. Consider implementing rate limiting or additional login throttling to further reduce abuse. Reources:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25136
PYSEC-2026-3056
GHSA-h79m-5jjm-jm4q
Jul 13, 2026
Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
SummaryA reflected Cross-site Scripting vulnerability was located in the rendering of the ExceptionMessage of the WebUI 500 error which could allow attackers to steal login session tokens of users who navigate to a specially crafted URL. DetailsThe WebUI error message renders PoC
Server response (excerpt):
XSS payload triggering (Displaying session token) when browsing to crafted URL When the WebUI inserts
XSS payload triggering (Displaying session token) on error when creating account key Server response (excerpt) contains ImpactAny authenticated WebUI user who follows a crafted link or triggers a request containing attacker-controlled input in a field that causes an error may execute arbitrary JavaScript in the WebUI origin. This vulnerability is more impactful due to the lack of protection of cookies (The Session token does not have HttpOnly attribute) and lack of Content Security Policy that would prevent thrid-party scripts from loading. Attackers can steal session cookies/tokens or perform actions as the victim like creating a new UserPass identity with an attacker known password. Example URL to Create UserPass for Root
Account Payload to Create UserPass
Creating identity for Root account via reflected XSS All WebUI users are impacted. Remediation / MitigationChange all client-side insertions of server-provided text from Additionally, consider adding a Content Security Policy (CSP) to mitigate external script execution and set the HTTPOnly flag for session cookies. Also, the API token should not be set in a JavaScript variable as it can be accessed by an attacker even with the HTTPOnly flag set on the session cookie.
References:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
35.8.2
patch
6 CVEs
CVE-2026-25736
PYSEC-2026-3055
GHSA-fq4f-4738-rqxm
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom RSE Attribute of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA stored XSS payload can be introduced via a custom RSE attribute value and is later rendered when the RSE is viewed. Create Path: Trigger Path: Request
Response
Storing XSS Payload in RSE Attribute XSS Payload triggering when viewing RSEImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25735
PYSEC-2026-3054
GHSA-8wpv-6x3f-3rm5
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Identity Name of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsThe identity name is stored and later rendered without output encoding. Create Path: Trigger Path: Request
Response
Storing XSS payload in account identity name Triggering XSS payload when viewing account ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
References
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25734
PYSEC-2026-3057
GHSA-h9fp-p2p9-873q
Jul 13, 2026
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the RSE metadata of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsSeveral metadata fields accept arbitrary input which is stored and later rendered unsafely in the WebUI when the RSEs are listed in the RSE Management dashboard. Create Path: Trigger Paths: Vulnerable Attributes: Request
Response
Stored XSS payload triggering in RSE listing after adding XSS payload in metadata ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25733
PYSEC-2026-3058
GHSA-rwj9-7j48-9f7q
Jul 13, 2026
Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom Rules function of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA malicious payload supplied in the Create Path: Trigger Paths:
Create Request
Response
Creating RSE with XSS payload in comment Reviewing rule creation requests XSS Payload triggering on rule review ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25138
PYSEC-2026-3053
GHSA-38wq-6q2w-hcf9
Jul 13, 2026
Rucio WebUI has Username Enumeration via Login Error Message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThe WebUI login endpoint returns distinct error messages depending on whether a supplied username exists, allowing unauthenticated attackers to enumerate valid usernames. DetailsWhen submitting invalid credentials to This behavioral difference allows an attacker to distinguish valid usernames from invalid ones by observing the response content. Proof of ConceptBogus Login (Non-existent Username "15251087")
Bogus Login (Existing Username "root", Wrong Password)
The difference in error messages confirms whether a username exists. ImpactAn unauthenticated attacker can enumerate valid usernames, which may be leveraged for targeted password guessing, credential stuffing, or social engineering attacks. Remediation / MitigationReturn a generic authentication failure message for all login errors, regardless of whether the username exists. Avoid disclosing account or identity existence through error responses. Consider implementing rate limiting or additional login throttling to further reduce abuse. Reources:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25136
PYSEC-2026-3056
GHSA-h79m-5jjm-jm4q
Jul 13, 2026
Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
SummaryA reflected Cross-site Scripting vulnerability was located in the rendering of the ExceptionMessage of the WebUI 500 error which could allow attackers to steal login session tokens of users who navigate to a specially crafted URL. DetailsThe WebUI error message renders PoC
Server response (excerpt):
XSS payload triggering (Displaying session token) when browsing to crafted URL When the WebUI inserts
XSS payload triggering (Displaying session token) on error when creating account key Server response (excerpt) contains ImpactAny authenticated WebUI user who follows a crafted link or triggers a request containing attacker-controlled input in a field that causes an error may execute arbitrary JavaScript in the WebUI origin. This vulnerability is more impactful due to the lack of protection of cookies (The Session token does not have HttpOnly attribute) and lack of Content Security Policy that would prevent thrid-party scripts from loading. Attackers can steal session cookies/tokens or perform actions as the victim like creating a new UserPass identity with an attacker known password. Example URL to Create UserPass for Root
Account Payload to Create UserPass
Creating identity for Root account via reflected XSS All WebUI users are impacted. Remediation / MitigationChange all client-side insertions of server-provided text from Additionally, consider adding a Content Security Policy (CSP) to mitigate external script execution and set the HTTPOnly flag for session cookies. Also, the API token should not be set in a JavaScript variable as it can be accessed by an attacker even with the HTTPOnly flag set on the session cookie.
References:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
39.0.0
major
6 CVEs
CVE-2026-25736
PYSEC-2026-3055
GHSA-fq4f-4738-rqxm
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom RSE Attribute of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA stored XSS payload can be introduced via a custom RSE attribute value and is later rendered when the RSE is viewed. Create Path: Trigger Path: Request
Response
Storing XSS Payload in RSE Attribute XSS Payload triggering when viewing RSEImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25735
PYSEC-2026-3054
GHSA-8wpv-6x3f-3rm5
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Identity Name of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsThe identity name is stored and later rendered without output encoding. Create Path: Trigger Path: Request
Response
Storing XSS payload in account identity name Triggering XSS payload when viewing account ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
References
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25734
PYSEC-2026-3057
GHSA-h9fp-p2p9-873q
Jul 13, 2026
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the RSE metadata of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsSeveral metadata fields accept arbitrary input which is stored and later rendered unsafely in the WebUI when the RSEs are listed in the RSE Management dashboard. Create Path: Trigger Paths: Vulnerable Attributes: Request
Response
Stored XSS payload triggering in RSE listing after adding XSS payload in metadata ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25733
PYSEC-2026-3058
GHSA-rwj9-7j48-9f7q
Jul 13, 2026
Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom Rules function of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA malicious payload supplied in the Create Path: Trigger Paths:
Create Request
Response
Creating RSE with XSS payload in comment Reviewing rule creation requests XSS Payload triggering on rule review ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25138
PYSEC-2026-3053
GHSA-38wq-6q2w-hcf9
Jul 13, 2026
Rucio WebUI has Username Enumeration via Login Error Message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThe WebUI login endpoint returns distinct error messages depending on whether a supplied username exists, allowing unauthenticated attackers to enumerate valid usernames. DetailsWhen submitting invalid credentials to This behavioral difference allows an attacker to distinguish valid usernames from invalid ones by observing the response content. Proof of ConceptBogus Login (Non-existent Username "15251087")
Bogus Login (Existing Username "root", Wrong Password)
The difference in error messages confirms whether a username exists. ImpactAn unauthenticated attacker can enumerate valid usernames, which may be leveraged for targeted password guessing, credential stuffing, or social engineering attacks. Remediation / MitigationReturn a generic authentication failure message for all login errors, regardless of whether the username exists. Avoid disclosing account or identity existence through error responses. Consider implementing rate limiting or additional login throttling to further reduce abuse. Reources:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25136
PYSEC-2026-3056
GHSA-h79m-5jjm-jm4q
Jul 13, 2026
Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
SummaryA reflected Cross-site Scripting vulnerability was located in the rendering of the ExceptionMessage of the WebUI 500 error which could allow attackers to steal login session tokens of users who navigate to a specially crafted URL. DetailsThe WebUI error message renders PoC
Server response (excerpt):
XSS payload triggering (Displaying session token) when browsing to crafted URL When the WebUI inserts
XSS payload triggering (Displaying session token) on error when creating account key Server response (excerpt) contains ImpactAny authenticated WebUI user who follows a crafted link or triggers a request containing attacker-controlled input in a field that causes an error may execute arbitrary JavaScript in the WebUI origin. This vulnerability is more impactful due to the lack of protection of cookies (The Session token does not have HttpOnly attribute) and lack of Content Security Policy that would prevent thrid-party scripts from loading. Attackers can steal session cookies/tokens or perform actions as the victim like creating a new UserPass identity with an attacker known password. Example URL to Create UserPass for Root
Account Payload to Create UserPass
Creating identity for Root account via reflected XSS All WebUI users are impacted. Remediation / MitigationChange all client-side insertions of server-provided text from Additionally, consider adding a Content Security Policy (CSP) to mitigate external script execution and set the HTTPOnly flag for session cookies. Also, the API token should not be set in a JavaScript variable as it can be accessed by an attacker even with the HTTPOnly flag set on the session cookie.
References:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
39.0.0rc2
pre
6 CVEs
CVE-2026-25736
PYSEC-2026-3055
GHSA-fq4f-4738-rqxm
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom RSE Attribute of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA stored XSS payload can be introduced via a custom RSE attribute value and is later rendered when the RSE is viewed. Create Path: Trigger Path: Request
Response
Storing XSS Payload in RSE Attribute XSS Payload triggering when viewing RSEImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25735
PYSEC-2026-3054
GHSA-8wpv-6x3f-3rm5
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Identity Name of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsThe identity name is stored and later rendered without output encoding. Create Path: Trigger Path: Request
Response
Storing XSS payload in account identity name Triggering XSS payload when viewing account ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
References
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25734
PYSEC-2026-3057
GHSA-h9fp-p2p9-873q
Jul 13, 2026
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the RSE metadata of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsSeveral metadata fields accept arbitrary input which is stored and later rendered unsafely in the WebUI when the RSEs are listed in the RSE Management dashboard. Create Path: Trigger Paths: Vulnerable Attributes: Request
Response
Stored XSS payload triggering in RSE listing after adding XSS payload in metadata ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25733
PYSEC-2026-3058
GHSA-rwj9-7j48-9f7q
Jul 13, 2026
Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom Rules function of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA malicious payload supplied in the Create Path: Trigger Paths:
Create Request
Response
Creating RSE with XSS payload in comment Reviewing rule creation requests XSS Payload triggering on rule review ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25138
PYSEC-2026-3053
GHSA-38wq-6q2w-hcf9
Jul 13, 2026
Rucio WebUI has Username Enumeration via Login Error Message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThe WebUI login endpoint returns distinct error messages depending on whether a supplied username exists, allowing unauthenticated attackers to enumerate valid usernames. DetailsWhen submitting invalid credentials to This behavioral difference allows an attacker to distinguish valid usernames from invalid ones by observing the response content. Proof of ConceptBogus Login (Non-existent Username "15251087")
Bogus Login (Existing Username "root", Wrong Password)
The difference in error messages confirms whether a username exists. ImpactAn unauthenticated attacker can enumerate valid usernames, which may be leveraged for targeted password guessing, credential stuffing, or social engineering attacks. Remediation / MitigationReturn a generic authentication failure message for all login errors, regardless of whether the username exists. Avoid disclosing account or identity existence through error responses. Consider implementing rate limiting or additional login throttling to further reduce abuse. Reources:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25136
PYSEC-2026-3056
GHSA-h79m-5jjm-jm4q
Jul 13, 2026
Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
SummaryA reflected Cross-site Scripting vulnerability was located in the rendering of the ExceptionMessage of the WebUI 500 error which could allow attackers to steal login session tokens of users who navigate to a specially crafted URL. DetailsThe WebUI error message renders PoC
Server response (excerpt):
XSS payload triggering (Displaying session token) when browsing to crafted URL When the WebUI inserts
XSS payload triggering (Displaying session token) on error when creating account key Server response (excerpt) contains ImpactAny authenticated WebUI user who follows a crafted link or triggers a request containing attacker-controlled input in a field that causes an error may execute arbitrary JavaScript in the WebUI origin. This vulnerability is more impactful due to the lack of protection of cookies (The Session token does not have HttpOnly attribute) and lack of Content Security Policy that would prevent thrid-party scripts from loading. Attackers can steal session cookies/tokens or perform actions as the victim like creating a new UserPass identity with an attacker known password. Example URL to Create UserPass for Root
Account Payload to Create UserPass
Creating identity for Root account via reflected XSS All WebUI users are impacted. Remediation / MitigationChange all client-side insertions of server-provided text from Additionally, consider adding a Content Security Policy (CSP) to mitigate external script execution and set the HTTPOnly flag for session cookies. Also, the API token should not be set in a JavaScript variable as it can be accessed by an attacker even with the HTTPOnly flag set on the session cookie.
References:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
39.0.0rc1
pre
6 CVEs
CVE-2026-25736
PYSEC-2026-3055
GHSA-fq4f-4738-rqxm
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom RSE Attribute of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA stored XSS payload can be introduced via a custom RSE attribute value and is later rendered when the RSE is viewed. Create Path: Trigger Path: Request
Response
Storing XSS Payload in RSE Attribute XSS Payload triggering when viewing RSEImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25735
PYSEC-2026-3054
GHSA-8wpv-6x3f-3rm5
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Identity Name of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsThe identity name is stored and later rendered without output encoding. Create Path: Trigger Path: Request
Response
Storing XSS payload in account identity name Triggering XSS payload when viewing account ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
References
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25734
PYSEC-2026-3057
GHSA-h9fp-p2p9-873q
Jul 13, 2026
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the RSE metadata of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsSeveral metadata fields accept arbitrary input which is stored and later rendered unsafely in the WebUI when the RSEs are listed in the RSE Management dashboard. Create Path: Trigger Paths: Vulnerable Attributes: Request
Response
Stored XSS payload triggering in RSE listing after adding XSS payload in metadata ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25733
PYSEC-2026-3058
GHSA-rwj9-7j48-9f7q
Jul 13, 2026
Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom Rules function of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA malicious payload supplied in the Create Path: Trigger Paths:
Create Request
Response
Creating RSE with XSS payload in comment Reviewing rule creation requests XSS Payload triggering on rule review ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25138
PYSEC-2026-3053
GHSA-38wq-6q2w-hcf9
Jul 13, 2026
Rucio WebUI has Username Enumeration via Login Error Message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThe WebUI login endpoint returns distinct error messages depending on whether a supplied username exists, allowing unauthenticated attackers to enumerate valid usernames. DetailsWhen submitting invalid credentials to This behavioral difference allows an attacker to distinguish valid usernames from invalid ones by observing the response content. Proof of ConceptBogus Login (Non-existent Username "15251087")
Bogus Login (Existing Username "root", Wrong Password)
The difference in error messages confirms whether a username exists. ImpactAn unauthenticated attacker can enumerate valid usernames, which may be leveraged for targeted password guessing, credential stuffing, or social engineering attacks. Remediation / MitigationReturn a generic authentication failure message for all login errors, regardless of whether the username exists. Avoid disclosing account or identity existence through error responses. Consider implementing rate limiting or additional login throttling to further reduce abuse. Reources:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25136
PYSEC-2026-3056
GHSA-h79m-5jjm-jm4q
Jul 13, 2026
Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
SummaryA reflected Cross-site Scripting vulnerability was located in the rendering of the ExceptionMessage of the WebUI 500 error which could allow attackers to steal login session tokens of users who navigate to a specially crafted URL. DetailsThe WebUI error message renders PoC
Server response (excerpt):
XSS payload triggering (Displaying session token) when browsing to crafted URL When the WebUI inserts
XSS payload triggering (Displaying session token) on error when creating account key Server response (excerpt) contains ImpactAny authenticated WebUI user who follows a crafted link or triggers a request containing attacker-controlled input in a field that causes an error may execute arbitrary JavaScript in the WebUI origin. This vulnerability is more impactful due to the lack of protection of cookies (The Session token does not have HttpOnly attribute) and lack of Content Security Policy that would prevent thrid-party scripts from loading. Attackers can steal session cookies/tokens or perform actions as the victim like creating a new UserPass identity with an attacker known password. Example URL to Create UserPass for Root
Account Payload to Create UserPass
Creating identity for Root account via reflected XSS All WebUI users are impacted. Remediation / MitigationChange all client-side insertions of server-provided text from Additionally, consider adding a Content Security Policy (CSP) to mitigate external script execution and set the HTTPOnly flag for session cookies. Also, the API token should not be set in a JavaScript variable as it can be accessed by an attacker even with the HTTPOnly flag set on the session cookie.
References:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
38.5.1
patch
6 CVEs
CVE-2026-25736
PYSEC-2026-3055
GHSA-fq4f-4738-rqxm
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom RSE Attribute of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA stored XSS payload can be introduced via a custom RSE attribute value and is later rendered when the RSE is viewed. Create Path: Trigger Path: Request
Response
Storing XSS Payload in RSE Attribute XSS Payload triggering when viewing RSEImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25735
PYSEC-2026-3054
GHSA-8wpv-6x3f-3rm5
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Identity Name of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsThe identity name is stored and later rendered without output encoding. Create Path: Trigger Path: Request
Response
Storing XSS payload in account identity name Triggering XSS payload when viewing account ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
References
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25734
PYSEC-2026-3057
GHSA-h9fp-p2p9-873q
Jul 13, 2026
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the RSE metadata of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsSeveral metadata fields accept arbitrary input which is stored and later rendered unsafely in the WebUI when the RSEs are listed in the RSE Management dashboard. Create Path: Trigger Paths: Vulnerable Attributes: Request
Response
Stored XSS payload triggering in RSE listing after adding XSS payload in metadata ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25733
PYSEC-2026-3058
GHSA-rwj9-7j48-9f7q
Jul 13, 2026
Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom Rules function of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA malicious payload supplied in the Create Path: Trigger Paths:
Create Request
Response
Creating RSE with XSS payload in comment Reviewing rule creation requests XSS Payload triggering on rule review ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25138
PYSEC-2026-3053
GHSA-38wq-6q2w-hcf9
Jul 13, 2026
Rucio WebUI has Username Enumeration via Login Error Message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThe WebUI login endpoint returns distinct error messages depending on whether a supplied username exists, allowing unauthenticated attackers to enumerate valid usernames. DetailsWhen submitting invalid credentials to This behavioral difference allows an attacker to distinguish valid usernames from invalid ones by observing the response content. Proof of ConceptBogus Login (Non-existent Username "15251087")
Bogus Login (Existing Username "root", Wrong Password)
The difference in error messages confirms whether a username exists. ImpactAn unauthenticated attacker can enumerate valid usernames, which may be leveraged for targeted password guessing, credential stuffing, or social engineering attacks. Remediation / MitigationReturn a generic authentication failure message for all login errors, regardless of whether the username exists. Avoid disclosing account or identity existence through error responses. Consider implementing rate limiting or additional login throttling to further reduce abuse. Reources:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25136
PYSEC-2026-3056
GHSA-h79m-5jjm-jm4q
Jul 13, 2026
Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
SummaryA reflected Cross-site Scripting vulnerability was located in the rendering of the ExceptionMessage of the WebUI 500 error which could allow attackers to steal login session tokens of users who navigate to a specially crafted URL. DetailsThe WebUI error message renders PoC
Server response (excerpt):
XSS payload triggering (Displaying session token) when browsing to crafted URL When the WebUI inserts
XSS payload triggering (Displaying session token) on error when creating account key Server response (excerpt) contains ImpactAny authenticated WebUI user who follows a crafted link or triggers a request containing attacker-controlled input in a field that causes an error may execute arbitrary JavaScript in the WebUI origin. This vulnerability is more impactful due to the lack of protection of cookies (The Session token does not have HttpOnly attribute) and lack of Content Security Policy that would prevent thrid-party scripts from loading. Attackers can steal session cookies/tokens or perform actions as the victim like creating a new UserPass identity with an attacker known password. Example URL to Create UserPass for Root
Account Payload to Create UserPass
Creating identity for Root account via reflected XSS All WebUI users are impacted. Remediation / MitigationChange all client-side insertions of server-provided text from Additionally, consider adding a Content Security Policy (CSP) to mitigate external script execution and set the HTTPOnly flag for session cookies. Also, the API token should not be set in a JavaScript variable as it can be accessed by an attacker even with the HTTPOnly flag set on the session cookie.
References:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
38.5.0
minor
6 CVEs
CVE-2026-25736
PYSEC-2026-3055
GHSA-fq4f-4738-rqxm
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom RSE Attribute of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA stored XSS payload can be introduced via a custom RSE attribute value and is later rendered when the RSE is viewed. Create Path: Trigger Path: Request
Response
Storing XSS Payload in RSE Attribute XSS Payload triggering when viewing RSEImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25735
PYSEC-2026-3054
GHSA-8wpv-6x3f-3rm5
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Identity Name of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsThe identity name is stored and later rendered without output encoding. Create Path: Trigger Path: Request
Response
Storing XSS payload in account identity name Triggering XSS payload when viewing account ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
References
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25734
PYSEC-2026-3057
GHSA-h9fp-p2p9-873q
Jul 13, 2026
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the RSE metadata of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsSeveral metadata fields accept arbitrary input which is stored and later rendered unsafely in the WebUI when the RSEs are listed in the RSE Management dashboard. Create Path: Trigger Paths: Vulnerable Attributes: Request
Response
Stored XSS payload triggering in RSE listing after adding XSS payload in metadata ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25733
PYSEC-2026-3058
GHSA-rwj9-7j48-9f7q
Jul 13, 2026
Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom Rules function of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA malicious payload supplied in the Create Path: Trigger Paths:
Create Request
Response
Creating RSE with XSS payload in comment Reviewing rule creation requests XSS Payload triggering on rule review ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25138
PYSEC-2026-3053
GHSA-38wq-6q2w-hcf9
Jul 13, 2026
Rucio WebUI has Username Enumeration via Login Error Message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThe WebUI login endpoint returns distinct error messages depending on whether a supplied username exists, allowing unauthenticated attackers to enumerate valid usernames. DetailsWhen submitting invalid credentials to This behavioral difference allows an attacker to distinguish valid usernames from invalid ones by observing the response content. Proof of ConceptBogus Login (Non-existent Username "15251087")
Bogus Login (Existing Username "root", Wrong Password)
The difference in error messages confirms whether a username exists. ImpactAn unauthenticated attacker can enumerate valid usernames, which may be leveraged for targeted password guessing, credential stuffing, or social engineering attacks. Remediation / MitigationReturn a generic authentication failure message for all login errors, regardless of whether the username exists. Avoid disclosing account or identity existence through error responses. Consider implementing rate limiting or additional login throttling to further reduce abuse. Reources:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25136
PYSEC-2026-3056
GHSA-h79m-5jjm-jm4q
Jul 13, 2026
Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
SummaryA reflected Cross-site Scripting vulnerability was located in the rendering of the ExceptionMessage of the WebUI 500 error which could allow attackers to steal login session tokens of users who navigate to a specially crafted URL. DetailsThe WebUI error message renders PoC
Server response (excerpt):
XSS payload triggering (Displaying session token) when browsing to crafted URL When the WebUI inserts
XSS payload triggering (Displaying session token) on error when creating account key Server response (excerpt) contains ImpactAny authenticated WebUI user who follows a crafted link or triggers a request containing attacker-controlled input in a field that causes an error may execute arbitrary JavaScript in the WebUI origin. This vulnerability is more impactful due to the lack of protection of cookies (The Session token does not have HttpOnly attribute) and lack of Content Security Policy that would prevent thrid-party scripts from loading. Attackers can steal session cookies/tokens or perform actions as the victim like creating a new UserPass identity with an attacker known password. Example URL to Create UserPass for Root
Account Payload to Create UserPass
Creating identity for Root account via reflected XSS All WebUI users are impacted. Remediation / MitigationChange all client-side insertions of server-provided text from Additionally, consider adding a Content Security Policy (CSP) to mitigate external script execution and set the HTTPOnly flag for session cookies. Also, the API token should not be set in a JavaScript variable as it can be accessed by an attacker even with the HTTPOnly flag set on the session cookie.
References:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
38.4.0
minor
6 CVEs
CVE-2026-25736
PYSEC-2026-3055
GHSA-fq4f-4738-rqxm
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom RSE Attribute of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA stored XSS payload can be introduced via a custom RSE attribute value and is later rendered when the RSE is viewed. Create Path: Trigger Path: Request
Response
Storing XSS Payload in RSE Attribute XSS Payload triggering when viewing RSEImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25735
PYSEC-2026-3054
GHSA-8wpv-6x3f-3rm5
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Identity Name of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsThe identity name is stored and later rendered without output encoding. Create Path: Trigger Path: Request
Response
Storing XSS payload in account identity name Triggering XSS payload when viewing account ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
References
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25734
PYSEC-2026-3057
GHSA-h9fp-p2p9-873q
Jul 13, 2026
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the RSE metadata of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsSeveral metadata fields accept arbitrary input which is stored and later rendered unsafely in the WebUI when the RSEs are listed in the RSE Management dashboard. Create Path: Trigger Paths: Vulnerable Attributes: Request
Response
Stored XSS payload triggering in RSE listing after adding XSS payload in metadata ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25733
PYSEC-2026-3058
GHSA-rwj9-7j48-9f7q
Jul 13, 2026
Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom Rules function of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA malicious payload supplied in the Create Path: Trigger Paths:
Create Request
Response
Creating RSE with XSS payload in comment Reviewing rule creation requests XSS Payload triggering on rule review ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25138
PYSEC-2026-3053
GHSA-38wq-6q2w-hcf9
Jul 13, 2026
Rucio WebUI has Username Enumeration via Login Error Message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThe WebUI login endpoint returns distinct error messages depending on whether a supplied username exists, allowing unauthenticated attackers to enumerate valid usernames. DetailsWhen submitting invalid credentials to This behavioral difference allows an attacker to distinguish valid usernames from invalid ones by observing the response content. Proof of ConceptBogus Login (Non-existent Username "15251087")
Bogus Login (Existing Username "root", Wrong Password)
The difference in error messages confirms whether a username exists. ImpactAn unauthenticated attacker can enumerate valid usernames, which may be leveraged for targeted password guessing, credential stuffing, or social engineering attacks. Remediation / MitigationReturn a generic authentication failure message for all login errors, regardless of whether the username exists. Avoid disclosing account or identity existence through error responses. Consider implementing rate limiting or additional login throttling to further reduce abuse. Reources:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25136
PYSEC-2026-3056
GHSA-h79m-5jjm-jm4q
Jul 13, 2026
Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
SummaryA reflected Cross-site Scripting vulnerability was located in the rendering of the ExceptionMessage of the WebUI 500 error which could allow attackers to steal login session tokens of users who navigate to a specially crafted URL. DetailsThe WebUI error message renders PoC
Server response (excerpt):
XSS payload triggering (Displaying session token) when browsing to crafted URL When the WebUI inserts
XSS payload triggering (Displaying session token) on error when creating account key Server response (excerpt) contains ImpactAny authenticated WebUI user who follows a crafted link or triggers a request containing attacker-controlled input in a field that causes an error may execute arbitrary JavaScript in the WebUI origin. This vulnerability is more impactful due to the lack of protection of cookies (The Session token does not have HttpOnly attribute) and lack of Content Security Policy that would prevent thrid-party scripts from loading. Attackers can steal session cookies/tokens or perform actions as the victim like creating a new UserPass identity with an attacker known password. Example URL to Create UserPass for Root
Account Payload to Create UserPass
Creating identity for Root account via reflected XSS All WebUI users are impacted. Remediation / MitigationChange all client-side insertions of server-provided text from Additionally, consider adding a Content Security Policy (CSP) to mitigate external script execution and set the HTTPOnly flag for session cookies. Also, the API token should not be set in a JavaScript variable as it can be accessed by an attacker even with the HTTPOnly flag set on the session cookie.
References:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
38.3.0
minor
6 CVEs
CVE-2026-25736
PYSEC-2026-3055
GHSA-fq4f-4738-rqxm
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom RSE Attribute of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA stored XSS payload can be introduced via a custom RSE attribute value and is later rendered when the RSE is viewed. Create Path: Trigger Path: Request
Response
Storing XSS Payload in RSE Attribute XSS Payload triggering when viewing RSEImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25735
PYSEC-2026-3054
GHSA-8wpv-6x3f-3rm5
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Identity Name of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsThe identity name is stored and later rendered without output encoding. Create Path: Trigger Path: Request
Response
Storing XSS payload in account identity name Triggering XSS payload when viewing account ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
References
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25734
PYSEC-2026-3057
GHSA-h9fp-p2p9-873q
Jul 13, 2026
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the RSE metadata of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsSeveral metadata fields accept arbitrary input which is stored and later rendered unsafely in the WebUI when the RSEs are listed in the RSE Management dashboard. Create Path: Trigger Paths: Vulnerable Attributes: Request
Response
Stored XSS payload triggering in RSE listing after adding XSS payload in metadata ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25733
PYSEC-2026-3058
GHSA-rwj9-7j48-9f7q
Jul 13, 2026
Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom Rules function of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA malicious payload supplied in the Create Path: Trigger Paths:
Create Request
Response
Creating RSE with XSS payload in comment Reviewing rule creation requests XSS Payload triggering on rule review ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25138
PYSEC-2026-3053
GHSA-38wq-6q2w-hcf9
Jul 13, 2026
Rucio WebUI has Username Enumeration via Login Error Message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThe WebUI login endpoint returns distinct error messages depending on whether a supplied username exists, allowing unauthenticated attackers to enumerate valid usernames. DetailsWhen submitting invalid credentials to This behavioral difference allows an attacker to distinguish valid usernames from invalid ones by observing the response content. Proof of ConceptBogus Login (Non-existent Username "15251087")
Bogus Login (Existing Username "root", Wrong Password)
The difference in error messages confirms whether a username exists. ImpactAn unauthenticated attacker can enumerate valid usernames, which may be leveraged for targeted password guessing, credential stuffing, or social engineering attacks. Remediation / MitigationReturn a generic authentication failure message for all login errors, regardless of whether the username exists. Avoid disclosing account or identity existence through error responses. Consider implementing rate limiting or additional login throttling to further reduce abuse. Reources:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25136
PYSEC-2026-3056
GHSA-h79m-5jjm-jm4q
Jul 13, 2026
Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
SummaryA reflected Cross-site Scripting vulnerability was located in the rendering of the ExceptionMessage of the WebUI 500 error which could allow attackers to steal login session tokens of users who navigate to a specially crafted URL. DetailsThe WebUI error message renders PoC
Server response (excerpt):
XSS payload triggering (Displaying session token) when browsing to crafted URL When the WebUI inserts
XSS payload triggering (Displaying session token) on error when creating account key Server response (excerpt) contains ImpactAny authenticated WebUI user who follows a crafted link or triggers a request containing attacker-controlled input in a field that causes an error may execute arbitrary JavaScript in the WebUI origin. This vulnerability is more impactful due to the lack of protection of cookies (The Session token does not have HttpOnly attribute) and lack of Content Security Policy that would prevent thrid-party scripts from loading. Attackers can steal session cookies/tokens or perform actions as the victim like creating a new UserPass identity with an attacker known password. Example URL to Create UserPass for Root
Account Payload to Create UserPass
Creating identity for Root account via reflected XSS All WebUI users are impacted. Remediation / MitigationChange all client-side insertions of server-provided text from Additionally, consider adding a Content Security Policy (CSP) to mitigate external script execution and set the HTTPOnly flag for session cookies. Also, the API token should not be set in a JavaScript variable as it can be accessed by an attacker even with the HTTPOnly flag set on the session cookie.
References:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
38.2.0
minor
6 CVEs
CVE-2026-25736
PYSEC-2026-3055
GHSA-fq4f-4738-rqxm
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom RSE Attribute of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA stored XSS payload can be introduced via a custom RSE attribute value and is later rendered when the RSE is viewed. Create Path: Trigger Path: Request
Response
Storing XSS Payload in RSE Attribute XSS Payload triggering when viewing RSEImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25735
PYSEC-2026-3054
GHSA-8wpv-6x3f-3rm5
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Identity Name of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsThe identity name is stored and later rendered without output encoding. Create Path: Trigger Path: Request
Response
Storing XSS payload in account identity name Triggering XSS payload when viewing account ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
References
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25734
PYSEC-2026-3057
GHSA-h9fp-p2p9-873q
Jul 13, 2026
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the RSE metadata of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsSeveral metadata fields accept arbitrary input which is stored and later rendered unsafely in the WebUI when the RSEs are listed in the RSE Management dashboard. Create Path: Trigger Paths: Vulnerable Attributes: Request
Response
Stored XSS payload triggering in RSE listing after adding XSS payload in metadata ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25733
PYSEC-2026-3058
GHSA-rwj9-7j48-9f7q
Jul 13, 2026
Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom Rules function of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA malicious payload supplied in the Create Path: Trigger Paths:
Create Request
Response
Creating RSE with XSS payload in comment Reviewing rule creation requests XSS Payload triggering on rule review ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25138
PYSEC-2026-3053
GHSA-38wq-6q2w-hcf9
Jul 13, 2026
Rucio WebUI has Username Enumeration via Login Error Message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThe WebUI login endpoint returns distinct error messages depending on whether a supplied username exists, allowing unauthenticated attackers to enumerate valid usernames. DetailsWhen submitting invalid credentials to This behavioral difference allows an attacker to distinguish valid usernames from invalid ones by observing the response content. Proof of ConceptBogus Login (Non-existent Username "15251087")
Bogus Login (Existing Username "root", Wrong Password)
The difference in error messages confirms whether a username exists. ImpactAn unauthenticated attacker can enumerate valid usernames, which may be leveraged for targeted password guessing, credential stuffing, or social engineering attacks. Remediation / MitigationReturn a generic authentication failure message for all login errors, regardless of whether the username exists. Avoid disclosing account or identity existence through error responses. Consider implementing rate limiting or additional login throttling to further reduce abuse. Reources:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25136
PYSEC-2026-3056
GHSA-h79m-5jjm-jm4q
Jul 13, 2026
Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
SummaryA reflected Cross-site Scripting vulnerability was located in the rendering of the ExceptionMessage of the WebUI 500 error which could allow attackers to steal login session tokens of users who navigate to a specially crafted URL. DetailsThe WebUI error message renders PoC
Server response (excerpt):
XSS payload triggering (Displaying session token) when browsing to crafted URL When the WebUI inserts
XSS payload triggering (Displaying session token) on error when creating account key Server response (excerpt) contains ImpactAny authenticated WebUI user who follows a crafted link or triggers a request containing attacker-controlled input in a field that causes an error may execute arbitrary JavaScript in the WebUI origin. This vulnerability is more impactful due to the lack of protection of cookies (The Session token does not have HttpOnly attribute) and lack of Content Security Policy that would prevent thrid-party scripts from loading. Attackers can steal session cookies/tokens or perform actions as the victim like creating a new UserPass identity with an attacker known password. Example URL to Create UserPass for Root
Account Payload to Create UserPass
Creating identity for Root account via reflected XSS All WebUI users are impacted. Remediation / MitigationChange all client-side insertions of server-provided text from Additionally, consider adding a Content Security Policy (CSP) to mitigate external script execution and set the HTTPOnly flag for session cookies. Also, the API token should not be set in a JavaScript variable as it can be accessed by an attacker even with the HTTPOnly flag set on the session cookie.
References:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
35.8.1
patch
6 CVEs
CVE-2026-25736
PYSEC-2026-3055
GHSA-fq4f-4738-rqxm
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom RSE Attribute of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA stored XSS payload can be introduced via a custom RSE attribute value and is later rendered when the RSE is viewed. Create Path: Trigger Path: Request
Response
Storing XSS Payload in RSE Attribute XSS Payload triggering when viewing RSEImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25735
PYSEC-2026-3054
GHSA-8wpv-6x3f-3rm5
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Identity Name of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsThe identity name is stored and later rendered without output encoding. Create Path: Trigger Path: Request
Response
Storing XSS payload in account identity name Triggering XSS payload when viewing account ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
References
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25734
PYSEC-2026-3057
GHSA-h9fp-p2p9-873q
Jul 13, 2026
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the RSE metadata of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsSeveral metadata fields accept arbitrary input which is stored and later rendered unsafely in the WebUI when the RSEs are listed in the RSE Management dashboard. Create Path: Trigger Paths: Vulnerable Attributes: Request
Response
Stored XSS payload triggering in RSE listing after adding XSS payload in metadata ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25733
PYSEC-2026-3058
GHSA-rwj9-7j48-9f7q
Jul 13, 2026
Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom Rules function of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA malicious payload supplied in the Create Path: Trigger Paths:
Create Request
Response
Creating RSE with XSS payload in comment Reviewing rule creation requests XSS Payload triggering on rule review ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25138
PYSEC-2026-3053
GHSA-38wq-6q2w-hcf9
Jul 13, 2026
Rucio WebUI has Username Enumeration via Login Error Message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThe WebUI login endpoint returns distinct error messages depending on whether a supplied username exists, allowing unauthenticated attackers to enumerate valid usernames. DetailsWhen submitting invalid credentials to This behavioral difference allows an attacker to distinguish valid usernames from invalid ones by observing the response content. Proof of ConceptBogus Login (Non-existent Username "15251087")
Bogus Login (Existing Username "root", Wrong Password)
The difference in error messages confirms whether a username exists. ImpactAn unauthenticated attacker can enumerate valid usernames, which may be leveraged for targeted password guessing, credential stuffing, or social engineering attacks. Remediation / MitigationReturn a generic authentication failure message for all login errors, regardless of whether the username exists. Avoid disclosing account or identity existence through error responses. Consider implementing rate limiting or additional login throttling to further reduce abuse. Reources:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25136
PYSEC-2026-3056
GHSA-h79m-5jjm-jm4q
Jul 13, 2026
Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
SummaryA reflected Cross-site Scripting vulnerability was located in the rendering of the ExceptionMessage of the WebUI 500 error which could allow attackers to steal login session tokens of users who navigate to a specially crafted URL. DetailsThe WebUI error message renders PoC
Server response (excerpt):
XSS payload triggering (Displaying session token) when browsing to crafted URL When the WebUI inserts
XSS payload triggering (Displaying session token) on error when creating account key Server response (excerpt) contains ImpactAny authenticated WebUI user who follows a crafted link or triggers a request containing attacker-controlled input in a field that causes an error may execute arbitrary JavaScript in the WebUI origin. This vulnerability is more impactful due to the lack of protection of cookies (The Session token does not have HttpOnly attribute) and lack of Content Security Policy that would prevent thrid-party scripts from loading. Attackers can steal session cookies/tokens or perform actions as the victim like creating a new UserPass identity with an attacker known password. Example URL to Create UserPass for Root
Account Payload to Create UserPass
Creating identity for Root account via reflected XSS All WebUI users are impacted. Remediation / MitigationChange all client-side insertions of server-provided text from Additionally, consider adding a Content Security Policy (CSP) to mitigate external script execution and set the HTTPOnly flag for session cookies. Also, the API token should not be set in a JavaScript variable as it can be accessed by an attacker even with the HTTPOnly flag set on the session cookie.
References:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
38.1.0
minor
6 CVEs
CVE-2026-25736
PYSEC-2026-3055
GHSA-fq4f-4738-rqxm
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom RSE Attribute of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA stored XSS payload can be introduced via a custom RSE attribute value and is later rendered when the RSE is viewed. Create Path: Trigger Path: Request
Response
Storing XSS Payload in RSE Attribute XSS Payload triggering when viewing RSEImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25735
PYSEC-2026-3054
GHSA-8wpv-6x3f-3rm5
Jul 13, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Identity Name of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsThe identity name is stored and later rendered without output encoding. Create Path: Trigger Path: Request
Response
Storing XSS payload in account identity name Triggering XSS payload when viewing account ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
References
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25734
PYSEC-2026-3057
GHSA-h9fp-p2p9-873q
Jul 13, 2026
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
6.1
/ 10
Medium
Network
Low
High
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the RSE metadata of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsSeveral metadata fields accept arbitrary input which is stored and later rendered unsafely in the WebUI when the RSEs are listed in the RSE Management dashboard. Create Path: Trigger Paths: Vulnerable Attributes: Request
Response
Stored XSS payload triggering in RSE listing after adding XSS payload in metadata ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25733
PYSEC-2026-3058
GHSA-rwj9-7j48-9f7q
Jul 13, 2026
Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
7.3
/ 10
High
Network
Low
Low
Required
Unchanged
High
High
None
SummaryA stored Cross-site Scripting (XSS) vulnerability was identified in the Custom Rules function of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. DetailsA malicious payload supplied in the Create Path: Trigger Paths:
Create Request
Response
Creating RSE with XSS payload in comment Reviewing rule creation requests XSS Payload triggering on rule review ImpactAny authenticated user who views affected resources may execute attacker-controlled JavaScript in the WebUI origin. Depending on the affected feature, this may impact all users or administrative users only. The impact is amplified by:
An attacker would likely attempt to exfiltrate the session token to an external site by setting an encoded version of the cookie as the path of a GET request to an attacker controlled site (i.e Attackers can also perform actions as the victim like creating a new UserPass identity with an attacker known password, creating/deleting an RSE, or exfiltrating data. XSS Payload to Create Root UserPass
Remediation / MitigationAll client-side renderings of server-provided or user-controlled data must ensure proper HTML escaping before insertion into the DOM. Unsafe methods such as Additional defense-in-depth measures include:
Resources
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25138
PYSEC-2026-3053
GHSA-38wq-6q2w-hcf9
Jul 13, 2026
Rucio WebUI has Username Enumeration via Login Error Message
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryThe WebUI login endpoint returns distinct error messages depending on whether a supplied username exists, allowing unauthenticated attackers to enumerate valid usernames. DetailsWhen submitting invalid credentials to This behavioral difference allows an attacker to distinguish valid usernames from invalid ones by observing the response content. Proof of ConceptBogus Login (Non-existent Username "15251087")
Bogus Login (Existing Username "root", Wrong Password)
The difference in error messages confirms whether a username exists. ImpactAn unauthenticated attacker can enumerate valid usernames, which may be leveraged for targeted password guessing, credential stuffing, or social engineering attacks. Remediation / MitigationReturn a generic authentication failure message for all login errors, regardless of whether the username exists. Avoid disclosing account or identity existence through error responses. Consider implementing rate limiting or additional login throttling to further reduce abuse. Reources:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25136
PYSEC-2026-3056
GHSA-h79m-5jjm-jm4q
Jul 13, 2026
Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
8.1
/ 10
High
Network
Low
None
Required
Unchanged
High
High
None
SummaryA reflected Cross-site Scripting vulnerability was located in the rendering of the ExceptionMessage of the WebUI 500 error which could allow attackers to steal login session tokens of users who navigate to a specially crafted URL. DetailsThe WebUI error message renders PoC
Server response (excerpt):
XSS payload triggering (Displaying session token) when browsing to crafted URL When the WebUI inserts
XSS payload triggering (Displaying session token) on error when creating account key Server response (excerpt) contains ImpactAny authenticated WebUI user who follows a crafted link or triggers a request containing attacker-controlled input in a field that causes an error may execute arbitrary JavaScript in the WebUI origin. This vulnerability is more impactful due to the lack of protection of cookies (The Session token does not have HttpOnly attribute) and lack of Content Security Policy that would prevent thrid-party scripts from loading. Attackers can steal session cookies/tokens or perform actions as the victim like creating a new UserPass identity with an attacker known password. Example URL to Create UserPass for Root
Account Payload to Create UserPass
Creating identity for Root account via reflected XSS All WebUI users are impacted. Remediation / MitigationChange all client-side insertions of server-provided text from Additionally, consider adding a Content Security Policy (CSP) to mitigate external script execution and set the HTTPOnly flag for session cookies. Also, the API token should not be set in a JavaScript variable as it can be accessed by an attacker even with the HTTPOnly flag set on the session cookie.
References:
Affected versions
1.10.0
1.10.0.post1
1.10.2
1.10.3
1.10.4
1.10.4.post1
1.10.5
1.10.6
1.11.0
1.11.0.post1
1.11.1
1.11.2
+ 440 more Show less
1.11.3
1.11.4
1.12.0
1.12.0.post1
1.12.1
1.12.2
1.12.2.post1
1.12.3
1.12.3.post1
1.12.4
1.12.5
1.12.5.post1
1.12.5.post2
1.12.6
1.13.0
1.13.0.post1
1.13.0.post2
1.13.1
1.13.2
1.14.0.post1
1.14.0.post2
1.14.1.post1
1.14.2
1.14.6
1.14.7
1.14.8
1.14.8.post1
1.14.8.post2
1.14.9
1.14.9.post1
1.15.0
1.15.0.post1
1.15.1
1.15.2
1.15.3
1.15.3.post1
1.15.4
1.15.4.post1
1.16.0
1.16.0.post1
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.2.post1
1.17.5
1.17.6
1.17.6.post1
1.17.6.post2
1.17.7
1.17.8
1.17.8.post1
1.17.8.post2
1.18.0
1.18.1
1.18.3
1.18.4
1.18.5
1.18.5.post1
1.18.6
1.18.6.post1
1.18.7
1.18.8
1.18.8.post1
1.18.9
1.19.0.post2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.4.post1
1.19.4.post2
1.19.5
1.19.6
1.19.7
1.19.7.post1
1.19.8
1.20.0
1.20.0rc1
1.20.1
1.20.1.post1
1.20.10
1.20.11
1.20.13
1.20.14
1.20.15
1.20.16
1.20.2
1.20.3
1.20.3rc1
1.20.3rc2
1.20.4
1.20.4.post1
1.20.4.post2
1.20.4rc1
1.20.4rc2
1.20.4rc3
1.20.5
1.20.6
1.20.7
1.20.8
1.20.9
1.21.0
1.21.0.dev1
1.21.0.post1
1.21.0.post2
1.21.0rc1
1.21.0rc2
1.21.0rc3
1.21.1
1.21.10
1.21.10.post1
1.21.12
1.21.2
1.21.3
1.21.4
1.21.5
1.21.6
1.21.7
1.21.8
1.22.0
1.22.0.dev1
1.22.0.dev2
1.22.0.dev3
1.22.0rc1
1.22.0rc2
1.22.1
1.22.2
1.22.3
1.22.3.post1
1.22.4
1.22.4.dev1
1.22.6
1.22.6.post1
1.22.7
1.22.8
1.22.8.post1
1.23.0
1.23.0rc1
1.23.0rc2
1.23.1
1.23.10
1.23.11
1.23.11.post1
1.23.11.post2
1.23.11.post3
1.23.11.post4
1.23.12
1.23.13
1.23.14
1.23.15
1.23.17
1.23.18
1.23.19
1.23.2
1.23.2.post1
1.23.2.post2
1.23.20
1.23.4
1.23.5
1.23.5.post1
1.23.6
1.23.6.post1
1.23.7
1.23.7.post1
1.23.8
1.23.9
1.23.9.post1
1.23.9.post2
1.23.9.post3
1.23.9.post4
1.24.0
1.24.0rc1
1.24.1
1.24.1.post1
1.24.1.post2
1.24.1.post3
1.24.1.post4
1.24.2
1.24.2.post1
1.24.3
1.24.3.post1
1.24.4
1.24.5
1.24.5.post1
1.25.0
1.25.0rc1
1.25.0rc2
1.25.1
1.25.1.post1
1.25.2
1.25.3
1.25.3.post1
1.25.3.post2
1.25.4
1.25.4.post1
1.25.5
1.25.6
1.25.7
1.26.0
1.26.0rc1
1.26.0rc2
1.26.1
1.26.1.post1
1.26.10
1.26.11
1.26.12
1.26.13
1.26.14
1.26.15
1.26.16
1.26.17
1.26.18
1.26.2
1.26.4
1.26.5
1.26.6
1.26.7
1.26.7.post1
1.26.8
1.26.8.post1
1.26.9
1.27.0
1.27.0.post1
1.27.0rc1
1.27.0rc2
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
1.5.10
1.5.11
1.5.11.post1
1.5.11.post2
1.5.12
1.6.0
1.6.0.post1
1.6.0.post2
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.7
1.6.8
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.5.post1
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
36.0.0
36.0.0.post1
36.0.0.post2
36.0.0rc1
36.0.0rc2
36.0.0rc3
36.0.0rc4
36.0.0rc5
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
39.0.0
39.0.0rc1
39.0.0rc2
39.1.0
39.2.0
39.3.0
Fixed in
35.8.3
38.5.4
39.3.1
References
Updated Jul 13, 2026 · Source: OSV.dev |