CVE-2026-90848

NameCVE-2026-90848
DescriptionA weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of the argument ResultMessage can lead to cross site scripting. The attack can be launched remotely. Upgrading to version 2.5.5 is able to address this issue. It is recommended to upgrade the affected component. This CVE was requested by the vendor.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ausweisapp2 (PTS)bookworm1.26.2-1vulnerable
trixie2.3.1-1vulnerable
forky, sid2.5.5-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ausweisapp2source(unstable)2.5.5-1

Notes

https://github.com/Governikus/AusweisApp/commit/6724c548f9ab5f50d674960b5e2a736318815089 (2.5.5)

Search for package or bug name: Reporting problems