CVE-2026-55081 Details
Description
DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. The DHIS2 OpenAPI HTML endpoint reflected values from the `scope` query parameter into the generated HTML document without sufficient sanitization. A crafted `scope` value could be rendered as active HTML or JavaScript in the OpenAPI documentation page. An attacker able to get a user to open a crafted OpenAPI HTML URL could execute JavaScript in that user's browser in the DHIS2 origin. Affected versions: DHIS2 2.42 and 2.43 before the 2026-06-09 security patch releases, and the development branch for DHIS2 2.44 before the fix was merged. Patched in 2.42.5.1, 2.43.0.1, the 2.42 and 2.43 line branches, and the 2.44 development branch.
A reflected cross-site scripting vulnerability has been identified in the DHIS2 OpenAPI HTML endpoint. Affected versions include DHIS2 2.42 and 2.43 prior to the 2026-06-09 security patch releases, as well as the development branch for DHIS2 2.44 before the fix was merged. The vulnerability arises because the endpoint reflected values from the 'scope' query parameter into the generated HTML document without adequate sanitization. This lack of proper input handling allowed a crafted 'scope' value to be rendered as active HTML or JavaScript on the OpenAPI documentation page. As a result, an attacker could potentially execute JavaScript in the context of the user's browser within the DHIS2 origin by getting them to open a specially crafted OpenAPI HTML URL.
Users are advised to upgrade to DHIS2 versions 2.42.5.1, 2.43.0.1, or the 2.44 development branch after the fix was applied. The patched versions sanitize the 'scope' input before it is rendered in the OpenAPI HTML document.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 21, 2026CISA-ADP
Assessed Jul 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/dhis2/dhis2-core/pull/24158 | [email protected] | Issue TrackingVendor |
| https://github.com/dhis2/dhis2-core/pull/24159 | [email protected] | Issue TrackingVendor |
| https://github.com/dhis2/dhis2-core/pull/24160 | [email protected] | Issue TrackingVendor |
| https://github.com/dhis2/dhis2-core/pull/24161 | [email protected] | Issue TrackingVendor |
| https://github.com/dhis2/dhis2-core/pull/24162 | [email protected] | Issue TrackingVendor |
| https://github.com/dhis2/dhis2-core/security/advisories/GHSA-6785-hj47-c27h | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| DHIS2 | >= 2.42, < 2.42.5.1 >= 2.43.0, < 2.43.0.1 ~2.44 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Modified | CISA-ADP |
| Jul 21, 2026 | New CVE Received | [email protected] |
Volerion