[go: up one dir, main page]

CVE-2025-11146

NameCVE-2025-11146
DescriptionReflected Cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows an attacker to execute malicious scripts (XSS) in the web management application. The vulnerability is caused by improper handling of GET inputs included in the URL in “/acng-report.html”.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apt-cacher-ng (PTS)bullseye3.6.4-1vulnerable
bookworm3.7.4-1vulnerable
forky, sid, trixie3.7.5-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
apt-cacher-ngsource(unstable)3.7.5-1

Notes

[bookworm] - apt-cacher-ng <no-dsa> (Minor issue)
https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-apt-cacher-ng
https://salsa.debian.org/blade/apt-cacher-ng/-/commit/b03d9a3ab326aad2538f42d2831b3114b830912b (upstream/3.7.5)

Search for package or bug name: Reporting problems