CVE-2026-12975
A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without enabling secure process
CVSS
8.5
High
EPSS
0.4%
p35
KEV
—
Exploit Today
11
0-100
Published: Jun 25, 2026 · Last modified: Aug 26, 2026 · CWE-611
0.4%EPSS · 30 days0.4%
2026-08-272026-09-25
A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without enabling secure processing features or disabling external entity resolution. An attacker with artifact-write permission (or unauthenticated when the registry runs with default configuration) can upload a crafted XML document to trigger blind server-side request forgery (SSRF) via external DTD/entity fetch, or cause denial of service via entity expansion.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:59360
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-12975
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2491688
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:59360
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-12975
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2491688
- security.access.redhat.comhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12975.json
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-930306.5 MED—
——0FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw.4hCVE-2026-617419.3 CRI19.7%
——6http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInstance` without any security configuration. With the JDK's default settings, the parser resolves DOCTYPE declarations, external general and parameter entities, and external DTDs.An application that uses these decoders to parse untrusted XML is vulnerable to XML External Entity (XXE) attacks. An attacker can craft a request that discloses local files readable by the service process, performs server-side request forgery (SSRF) against internal network resources, and/or causes denial of service through entity expansion. Versions 0.24.1 and 1.0.0-M39 fix the issue.1dCVE-2026-815367.7 HIG18.1%
——5IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.1dCVE-2026-181847.4 HIG11.2%
——3IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.2dCVE-2026-181727.4 HIG9.3%
——3IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references.2dCVE-2026-176468.5 HIG19.5%
——6IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper restriction of XML external entity references.2d