XML External Entity injection in Apache CXF - CVE-2026-49875
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper restriction of XML external entity reference in W3CMultiSchemaFactory and EndpointReferenceUtils when parsing XML input. A remote attacker can supply crafted XML containing external entity references to disclose sensitive information.
The issue enables out-of-band external entity resolution.
Affected software
Red Hat Camel for Spring Boot
How to mitigate CVE-2026-49875
Red Hat Camel for Spring Boot - update to 4.18