CVE-2026-49875
Vulnerability Description
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB)
external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.
external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-611
Source
NVD
Vendor
Apache Software Foundation
Product
Apache CXF
Discussion (0)
Add Comment
No comments yet. Be the first!