PatchSiren

dhis2 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH dhis2 CVE published 2026-07-21

CVE-2026-55081

The DHIS2 OpenAPI HTML endpoint reflected values from the `scope` query parameter into the generated HTML document without sufficient sanitization, allowing a crafted `scope` value to be rendered as active HTML or JavaScript. This vulnerability affects DHIS2 versions 2.42 and 2.43 before the 2026-06-09 security patch releases, and the development branch for DHIS2 2.44 before the fix was merged. Users of t [truncated]