CVE-2026-65432: Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any or referenced from tha
Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <xsd:import> referenced from that top-level WSDL is handed off to WSDL4J, which does not disable DOCTYPE declarations or external entities. As a result, the protections applied to the top-level document do not extend to imported documents, leaving imported WSDL/XSD content vulnerable to XML External Entity (XXE) attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-65432
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-65432 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Apache CXF: Multiple Vulnerabilitiescert-bund
More from NVD Recent CVEs
- unknownCVE-2026-66909: Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native…2026-08-06
- unknownCVE-2026-64958: An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of se…2026-08-06
- unknownCVE-2026-57819: Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the …2026-08-06
- unknownCVE-2026-57817: The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` para…2026-08-06
- unknownCVE-2026-54225: Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior …2026-08-06