Input validation error in minio-java - CVE-2025-59952
Published: October 28, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to the application automatically substitutes XML tag values containing references to system properties or environment variables. A remote attacker can pass a specially crafted XML file to the application and obtain sensitive information.
Affected software
IBM Observability with Instana
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat Camel for Spring Boot
How to mitigate CVE-2025-59952
IBM Observability with Instana - update to 1.0.309
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3
Red Hat Camel for Spring Boot - addressed in versions 4.10.7, 4.14