GHSA-xw5h-cmh3-8j6jCriticalCVSS 9.8

Apache CXF has Improper Restriction of XML External Entity Reference

Published
June 12, 2026
Last Modified
October 2, 2026

🔗 CVE IDs covered (1)

📋 Description

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.

🎯 Affected products2

  • maven/org.apache.cxf:cxf-core:>= 4.2.0, < 4.2.2
  • maven/org.apache.cxf:cxf-core:< 4.1.7

🔗 References (10)