CVE-2026-44228

NameCVE-2026-44228
DescriptionRT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Scripting (XSS) vulnerability, where user-controlled data is rendered without proper HTML escaping. An authenticated user with permission to set the relevant data can inject JavaScript that executes when another RT user views the affected page. This issue has been fixed in version 6.0.3.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
request-tracker5 (PTS)bookworm, bookworm (security)5.0.3+dfsg-3~deb12u6fixed
trixie (security), trixie5.0.7+dfsg-4+deb13u3fixed
forky, sid5.0.10+dfsg-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
request-tracker5source(unstable)(not affected)

Notes

- request-tracker5 <not-affected> (Only affects RT6)

Search for package or bug name: Reporting problems