CVE-2026-29519 fix for lucee 6.2?

Hello I have spotted the recent CVE-2026-29519. I cant find any mention of the this CVE in Jira Lucee Dev or in this forum.

Only a small number of Lucee 6.2 versions are listed as vulnerable incl. 6.2.3.35 and no 6.2s are listed as not vulnerable.

Quick testing reveals our 6.2 Apps to not be vulnerable in situ. but that does mean the underlying Lucee version is not.

Does anyone know if this issue has been addressed in any releases post 6.2.3.35 ?

If this is the wrong channel for this sort of question, let me know :slight_smile:

Many thanks.

JC

@jvc ,
I tested the published PoC on both Linux (Docker) and Windows. I was able to reproduce the reported XSS behavior on Linux, but not on Windows. On Windows, the request results in a standard missinginclude error without JavaScript execution.
https://luceeserver.atlassian.net/browse/LDEV-3027