Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-88789— Apache Camel Quarkus: Camel Quarkus: Forced Xalan TransformerFactory drops upstream external-DTD/stylesheet hardening

Quick assessment

Affected
Apache Software Foundation Apache Camel Quarkus
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Camel Quarkus 中 XSLT 支持扩展(camel-quarkus-support-xalan)存在 XML 外部实体引用限制不当漏洞。该漏洞影响所有平台上的 Apache Camel Quarkus 3.2.0 至 3.33.3(不含)以及 3.34.0 至 3.40.0(不含)版本。攻击者若能提供待转换的 XML 文档,即可通过在该文档中声明外部实体来读取本地文件或向内部网络位置发起请求。 该扩展为 xslt 组件提供了基于 Xalan 的 TransformerFactory,并将其

CVSS 8.6 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-88789

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Camel Quarkus: Camel Quarkus: Forced Xalan TransformerFactory drops upstream external-DTD/stylesheet hardening
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Restriction of XML External Entity Reference in the XSLT support extension (camel-quarkus-support-xalan) in Apache Camel Quarkus from 3.2.0 before 3.33.3 and from 3.34.0 before 3.40.0 on all platforms allows an attacker who supplies the XML document being transformed to read local files or issue requests to internal network locations via an external entity declaration in that document. The extension supplies its own Xalan-backed TransformerFactory to the xslt component and registers it as the JAXP default. Xalan-J 2.7.x predates JAXP 1.5 and does not honour javax.xml.XMLConstants.ACCESS_EXTERNAL_DTD or ACCESS_EXTERNAL_STYLESHEET, so the external access restrictions Apache Camel applies to the TransformerFactory it creates were not in effect. On the xslt component path this affects message bodies that reach the transformer already as a javax.xml.transform.Source; bodies of other types are converted to a SAXSource by Apache Camel with external entities and external DTD loading disabled, and are not affected. Because the factory is also the JAXP default, other code in the application obtaining one through TransformerFactory.newInstance() loses the same restrictions without error. Applications are affected if they use any of camel-quarkus-xslt, camel-quarkus-xslt-saxon, camel-quarkus-tika or camel-quarkus-xmlsecurity, each of which brings the XSLT support extension onto the classpath. For all but camel-quarkus-xslt, the exposure is limited to the JAXP default factory, since those extensions do not perform XSLT transformations themselves. Users are recommended to upgrade to version 3.33.3 or 3.40.0, which fixes this issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
XML外部实体引用的不恰当限制(XXE)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Camel Quarkus 3.2.0 ~ 3.33.3 -

II. Public POCs for CVE-2026-88789

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-88789

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-88789 (2)

Vendor Advisories for CVE-2026-88789 (1)

Other References for CVE-2026-88789 (1)

Same Patch Batch · Apache Software Foundation · 2026-10-01 · 28 CVEs total

CVE-2026-94250 8.2 HIGH Apache APISIX: Batch response aggregation can exhaust worker memory
CVE-2026-94212 6.4 MEDIUM Apache APISIX: unauthenticated impersonation issue in saml-auth
CVE-2026-94269 6.3 MEDIUM Apache APISIX: Servlet-style normalization creates a route/upstream authorization mismatch
CVE-2026-78242 5.7 MEDIUM Apache APISIX: data-mask may fail to redact request headers in logger output
CVE-2026-82806 5.3 MEDIUM Apache APISIX: cross-request permission pollution via static permission list mutation
CVE-2026-94276 5.1 MEDIUM Apache APISIX: Openid-connect introspection validation issue
CVE-2026-94220 2.1 LOW Apache APISIX: session fixation issue in feishu-auth and dingtalk-auth plugin
CVE-2026-56154 Apache HTTP Server: mod_rewrite use-after-free via %{LA-U:HTTP:...}
CVE-2026-42528 Apache HTTP Server: mod_dav shared lock overflow
CVE-2026-42356 Apache HTTP Server: limited RCE for some internal redirects to non-CGI files in CGI direct
CVE-2026-46729 Apache HTTP Server: mod_heartmonitor denial of service
CVE-2026-47360 Apache HTTP Server: mod_session: Session cookie not removed during internal redirect
CVE-2026-48005 Apache HTTP Server: mod_auth_digest reauthentication attack
CVE-2026-56153 Apache HTTP Server: mod_charset_lite: Heap overflow in finish_partial_char
CVE-2026-63686 Apache HTTP Server: mod_xml2enc crash on charset conversion failure
CVE-2026-56449 Apache HTTP Server: mod_proxy_html: crash in dump_content
CVE-2026-57941 Apache HTTP Server: mod_http2 use-after-free / wild write via shared session->bbtmp re-ent
CVE-2026-58415 Apache HTTP Server: mod_dav_fs property database read access
CVE-2026-59685 Apache HTTP Server: Out-of-Bounds Write in ap_directory_walk() Canonical-Name Rewrite on C
CVE-2026-59797 Apache HTTP Server: mod_ssl SSLRequire allows .htaccess ap_expr file-function

Showing top 20 of 28 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-88789

No comments yet


Leave a comment