CVE-2026-44229
Description
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a Cross-Site Scripting (XSS) vulnerability where uploaded content is served inline rather than as an attachment. An authenticated user who can upload content can include JavaScript in the upload that will execute in the browser session of any RT user who later views or downloads it. This issue has been fixed in versions 5.0.10 and 6.0.3.
How to fix CVE-2026-44229
To remediate CVE-2026-44229, upgrade the affected package to a fixed version below.
- Debian/request-tracker4—no fix listed
- Debian/request-tracker5—upgrade to 5.0.3+dfsg-3~deb12u6 or later
Is CVE-2026-44229 being exploited?
No exploitation signal available. Neither CISA KEV nor a current EPSS score has been published for CVE-2026-44229.
Affected packages (2)
- from 0
- from 0, < 5.0.3+dfsg-3~deb12u6