cbcvebase.

Redhat Build Of Apicurio Registry vulnerabilities

3 known vulnerabilities affecting redhat/build_of_apicurio_registry.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2026-12975P3HIGHCVSS 8.5≥ 3.0, ≤ 3.22026-06-25
CVE-2026-12975 [HIGH] CWE-611 CVE-2026-12975: A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParse A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without enabling secure processing features or disabling external entity resolution. An attacker with artifact-write permission (or unauthenticated when the registry runs with default configuration) can upload a crafted XML document to trigger
nvd
CVE-2026-12992P3HIGHCVSS 7.4≥ 3.0, ≤ 3.22026-06-25
CVE-2026-12992 [HIGH] CWE-918 CVE-2026-12992: A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without di A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. When the VALIDITY rule is set to FULL, an attacker with Developer-role access can upload a WSDL document containing attacker-controlled import locations, causing the registry to issue HTTP requests to arbi
nvd
CVE-2026-12993P3MEDIUMCVSS 6.5≥ 3.0, ≤ 3.22026-06-26
CVE-2026-12993 [MEDIUM] CWE-776 CVE-2026-12993: A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE declarations or enable FEATURE_SECURE_PROCESSING. An attacker with artifact-write permission can upload XML documents with internal entity-expansion payloads (billion-laughs variant) that cause CPU and heap
nvd
Redhat Build Of Apicurio Registry vulnerabilities | cvebase