cbcvebase.
CVE-2026-65432
published 2026-08-06

CVE-2026-65432: Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any or referenced from that…

PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.41%
34.1th percentile
Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any or referenced from that top-level WSDL is handed off to WSDL4J, which does not disable DOCTYPE declarations or external entities. As a result, the protections applied to the top-level document do not extend to imported documents, leaving imported WSDL/XSD content vulnerable to XML External Entity (XXE) attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Affected

6 ranges
VendorProductVersion rangeFixed in
apachecxf< 3.6.123.6.12
apachecxf>= 4.0.0 < 4.1.84.1.8
apachecxf>= 4.2.0 < 4.2.34.2.3
apache_software_foundationapache_cxf< 3.6.123.6.12
apache_software_foundationapache_cxf>= 4.0.0 < 4.1.84.1.8
apache_software_foundationapache_cxf>= 4.2.0 < 4.2.34.2.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.