Vulnerability GHSA-xw5h-cmh3-8j6j

Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
3 months ago
June 12, 2026 at 12:31 PM UTC
Apache CXF has Improper Restriction of XML External Entity Reference
4.2.0 - 4.2.1
4.2.0 - 4.2.1

Summary

Apache CXF has Improper Restriction of XML External Entity Reference

Details

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.

Impacted packages

Timeline

Published
3 months ago
June 12, 2026 at 12:31 PM UTC
Fixed (4.2.2)
Unknown
Unknown
Fixed (4.1.7)
Unknown
Unknown
Last Modified
9 hours ago
October 02, 2026 at 11:30 PM UTC