CVE-2026-49875
published 2026-06-12CVE-2026-49875: Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations…
PriorityP352critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.53%
41.1th percentile
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB)
external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | < 4.1.7 | 4.1.7 |
| apache | cxf | >= 4.2.0 < 4.2.2 | 4.2.2 |
| apache_software_foundation | apache_cxf | < 4.1.7 | 4.1.7 |
| apache_software_foundation | apache_cxf | >= 4.2.0 < 4.2.2 | 4.2.2 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cxf: org.apache.cxf/cxf-core: Apache CXF: Information disclosure via out-of-band external entity resolution due to missing JAXP hardening
vendor_redhat·2026-06-12·CVSS 9.8
CVE-2026-49875 [CRITICAL] CWE-611 cxf: org.apache.cxf/cxf-core: Apache CXF: Information disclosure via out-of-band external entity resolution due to missing JAXP hardening
cxf: org.apache.cxf/cxf-core: Apache CXF: Information disclosure via out-of-band external entity resolution due to missing JAXP hardening
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB)
external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.
A flaw was found in Apache CXF. The EndpointReferenceUtils and W3CMultiSchemaFactory classes within Apache CXF construct a SAXParserFactory without proper security configurations. This oversight enables out-of-band (OOB) external entity resolution, a type of XML External Entity (XXE) vulnerability. A remote attacker could exploit this to disclose sensitive information
GHSA
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity reso
ghsa_unreviewed·2026-06-12
CVE-2026-49875 CWE-611 Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity reso
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB)
external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.
VulDB
Apache CXF up to 4.1.6/4.2.1 W3CMultiSchemaFactory/EndpointReferenceUtils xml external entity reference
vuldb·2026-06-11
CVE-2026-49875 [CRITICAL] Apache CXF up to 4.1.6/4.2.1 W3CMultiSchemaFactory/EndpointReferenceUtils xml external entity reference
A vulnerability identified as problematic has been detected in Apache CXF up to 4.1.6/4.2.1. Impacted is the function W3CMultiSchemaFactory/EndpointReferenceUtils. The manipulation leads to xml external entity reference.
This vulnerability is listed as CVE-2026-49875. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
https://lists.apache.org/thread/3kb9w5bg90xcp06fccoz9k3gpsvyy79ohttp://www.openwall.com/lists/oss-security/2026/06/11/2https://access.redhat.com/errata/RHSA-2026:36839https://access.redhat.com/errata/RHSA-2026:37390https://access.redhat.com/security/cve/CVE-2026-49875https://bugzilla.redhat.com/show_bug.cgi?id=2488309https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49875.json
2026-06-12
Published