CVE-2026-44229

EUVD-2026-46078
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a Cross-Site Scripting (XSS) vulnerability where uploaded content is served inline rather than as an attachment. An authenticated user who can upload content can include JavaScript in the upload that will execute in the browser session of any RT user who later views or downloads it. This issue has been fixed in versions 5.0.10 and 6.0.3.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 14.96%
Affected Products (NVD)
VendorProductVersion
bestpracticalrequest_tracker
5.0.0 ≤
𝑥
< 5.0.10
bestpracticalrequest_tracker
6.0.0 ≤
𝑥
< 6.0.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
request-tracker4
bookworm
4.4.6+dfsg-1.1+deb12u4
fixed
bookworm (security)
4.4.6+dfsg-1.1+deb12u4
fixed
request-tracker5
bookworm
5.0.3+dfsg-3~deb12u6
fixed
bookworm (security)
5.0.3+dfsg-3~deb12u6
fixed
forky
5.0.10+dfsg-3
fixed
sid
5.0.10+dfsg-3
fixed
trixie
5.0.7+dfsg-4+deb13u3
fixed
trixie (security)
5.0.7+dfsg-4+deb13u3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
request-tracker4
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
xenial
needs-triage
request-tracker5
jammy
Fixed 5.0.1+dfsg-1ubuntu1+esm2
released
noble
Fixed 5.0.5+dfsg-2ubuntu0.1~esm2
released
questing
ignored
resolute
Fixed 5.0.7+dfsg-6ubuntu0.1~esm1
released