# Kibana Cross-Site Scripting Vulnerability - Unencoded Character in JSON Response

**URL:** <https://discuss.elastic.co/t/kibana-cross-site-scripting-vulnerability-unencoded-character-in-json-response/385041>\
**Category:** Kibana\
**Created:** [February 13, 2026, 1:16pm UTC](https://discuss.elastic.co/t/kibana-cross-site-scripting-vulnerability-unencoded-character-in-json-response/385041 "2026-02-13T13:16:05Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rakesh\_Bhalani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rakesh_bhalani/32/146902_2.png) [@Rakesh\_Bhalani](https://discuss.elastic.co/u/Rakesh_Bhalani)\
**Post date:** [February 13, 2026, 1:16pm UTC](https://discuss.elastic.co/t/kibana-cross-site-scripting-vulnerability-unencoded-character-in-json-response/385041/1 "2026-02-13T13:16:05Z")

</div>

We have on-prime installation of kibana-8.14.0, It is being analyzed by the vulnerability detection tool Qualys, tool is reporting JSON response of following API as vulnerable to Cross-Site-Scripting

> Kibana API call made by Qualys tool to find vulnerability:

GET `https://my-kibana/api/exception_lists/items?<script>alert(45)</script>`

> Response from the API:

```auto
content-type: application/json

{
  "statusCode":400,
  "error":"Bad Request",
  "message": "[request query] : Invalid keys <script>alert(45)</script>"
}

```

Tool is reporting XSS vulnerability (Unencoded character) in the ‘message’ property of the API JSON response mentioned above.

Team is asking us to fix this by encoding the response content for html.

1. Is there any way Kibana API response content is html-encoded and safe to render on the client/UI side to prevent XSS
2. OR Kibana frontend take care of encoding response content to be safe for html before it renders in the UI and this is not a valid vulnerability finding?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 13, 2026, 1:42pm UTC](https://discuss.elastic.co/t/kibana-cross-site-scripting-vulnerability-unencoded-character-in-json-response/385041/2 "2026-02-13T13:42:59Z")

</div>

Hello and welcome,

Kibana 8.14 was released almost 2 years ago, there were multiple improvments and security fixes, the last version is 8.19.11.

You need to upgrade your stack, both Elasticsearch and Kibana, to the 8.19.11 and then check if this issue is still present.

Do you have the CVE being reported by Qualys? If so you may search the forum for this CVE to see if it was already fixed.
