CyberSec.Space Logo
CVEブラウザに戻る

CVE-2026-49875

PENDING
N/A
CVSS Severity Score
EPSS Score0.0500%
EPSS Percentile35.35th
Published2026年6月12日
Last Modified2026年6月12日

Vulnerability Description

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

関連する脆弱性情報