CyberSec.Space Logo
Back to CVE Browser

CVE-2026-49875

PENDING
N/A
CVSS Severity Score
EPSS Score0.0500%
EPSS Percentile35.35th
PublishedJun 12, 2026
Last ModifiedJun 12, 2026

Vulnerability Description

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

Related Vulnerabilities