The classifier judged this item not relevant to AI security, so it is left out of lists, feeds, the API and dataset releases. If that is wrong, report a correction on this page.
CVE-2026-88789: Improper Restriction of XML External Entity Reference in the XSLT support extension (camel-quarkus-support-xalan) in…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-88789
- Published
- Record updated
Summary
Apache Camel Quarkus versions 3.2.0 before 3.33.3 and 3.34.0 before 3.40.0 contain an XML External Entity flaw in the camel-quarkus-support-xalan XSLT extension, tracked as CVE-2026-88789. Because the extension registers a Xalan-J TransformerFactory that ignores the JAXP external access restrictions, an attacker who supplies the XML document being transformed can read local files or reach internal network locations via an external entity declaration. Applications using camel-quarkus-xslt, camel-quarkus-xslt-saxon, camel-quarkus-tika or camel-quarkus-xmlsecurity are affected.
Mitigation
Upgrade to version 3.33.3 or 3.40.0, which fixes this issue.