GHSA-57hc-mr64-vrxxHighCVSS 7.5

When XML batch processing is turned on and the XPath option is selected, the raw batch input goes...

Published
September 11, 2026
Last Modified
September 11, 2026

🔗 CVE IDs covered (1)

📋 Description

When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks.

🔗 References (4)