Multiple CVEs Identified for XSS Vulnerabilities in Jinja and Express

Multiple CVEs Identified for XSS Vulnerabilities in Jinja and Express

First seen 18 Feb 2026, 13:23 UTC Api.Msrc.Microsoft 39.1

Article Content

Browse articles
ThreatCluster

CVE-2024-22195 was published on January 11, 2024, detailing a Cross-Site Scripting (XSS) vulnerability in Jinja. Additionally, CVE-2024-43796, published on September 10, 2024, describes an XSS vulnerability in Express via the response.redirect() method. Both vulnerabilities could potentially affect applications utilizing these frameworks.

Timeline

2024-01-11
CVE-2024-22195 published
2024-09-10
CVE-2024-43796 published
2026-02-18
Articles published detailing both vulnerabilities