XML External Entity injection in dependency-track - #VU127086
Published: April 23, 2026
dependency-track
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information and cause a denial of service.
The vulnerability exists due to improper restriction of xml external entity reference in the CycloneDX BOM validator when validating uploaded BOMs in XML format. A remote user can upload a specially crafted XML BOM to disclose sensitive information and cause a denial of service.
Exploitation requires authentication and the BOM_UPLOAD permission.