6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Description
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB)
external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.
external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.
Basic Information
ID
CVE-2026-49875
Source
apache
Published
Jun 12, 2026 at 08:54
Modified
Jun 15, 2026 at 19:21
Affected Product
Vendor
Apache Software Foundation
Product
Apache CXF
Version
4.2.0
Affected Versions
Apache Software Foundation Apache CXF 4.2.0
Apache Software Foundation Apache CXF 0
Apache Software Foundation Apache CXF 0