CVE-2026-12993: Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') in Red Hat Red Hat build of Apicurio Registry 3
A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE declarations or enable FEATURE_SECURE_PROCESSING. An attacker with artifact-write permission can upload XML documents with internal entity-expansion payloads (billion-laughs variant) that cause CPU and heap exhaustion, partially mitigated by the JAXP default 64,000 entity-expansion limit.
AI Analysis
Technical Summary
The vulnerability in Red Hat build of Apicurio Registry 3 is due to the DocumentBuilderAccessor correctly blocking external DTD and schema access but failing to disable DOCTYPE declarations or enable FEATURE_SECURE_PROCESSING. This allows an attacker with artifact-write permissions to upload XML documents with internal entity expansion payloads, specifically the billion-laughs variant, which can exhaust CPU and heap resources. The JAXP default limit of 64,000 entity expansions provides partial mitigation. The CVSS 3.1 score is 6.5 (medium severity) with network attack vector, low attack complexity, requiring privileges (artifact-write), no user interaction, unchanged scope, no confidentiality or integrity impact, but high availability impact. No vendor advisory confirms a patch or fix at this time.
Potential Impact
Successful exploitation can cause denial of service through CPU and heap exhaustion on the affected system, impacting availability. There is no direct impact on confidentiality or integrity. The attack requires artifact-write permissions, limiting the attacker scope to authorized users who can upload artifacts.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-12993 for current remediation guidance. Until a fix is available, restrict artifact-write permissions to trusted users only and consider additional XML processing safeguards if possible. The default JAXP entity-expansion limit partially mitigates the risk.
CVE-2026-12993: Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') in Red Hat Red Hat build of Apicurio Registry 3
Description
A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE declarations or enable FEATURE_SECURE_PROCESSING. An attacker with artifact-write permission can upload XML documents with internal entity-expansion payloads (billion-laughs variant) that cause CPU and heap exhaustion, partially mitigated by the JAXP default 64,000 entity-expansion limit.
CVSS v3.1
Score 6.5medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Red Hat build of Apicurio Registry 3 is due to the DocumentBuilderAccessor correctly blocking external DTD and schema access but failing to disable DOCTYPE declarations or enable FEATURE_SECURE_PROCESSING. This allows an attacker with artifact-write permissions to upload XML documents with internal entity expansion payloads, specifically the billion-laughs variant, which can exhaust CPU and heap resources. The JAXP default limit of 64,000 entity expansions provides partial mitigation. The CVSS 3.1 score is 6.5 (medium severity) with network attack vector, low attack complexity, requiring privileges (artifact-write), no user interaction, unchanged scope, no confidentiality or integrity impact, but high availability impact. No vendor advisory confirms a patch or fix at this time.
Potential Impact
Successful exploitation can cause denial of service through CPU and heap exhaustion on the affected system, impacting availability. There is no direct impact on confidentiality or integrity. The attack requires artifact-write permissions, limiting the attacker scope to authorized users who can upload artifacts.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-12993 for current remediation guidance. Until a fix is available, restrict artifact-write permissions to trusted users only and consider additional XML processing safeguards if possible. The default JAXP entity-expansion limit partially mitigates the risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-06-23T12:18:15.412Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-12993","vendor":"Red Hat"}]
Threat ID: 6a3dbdc04853345fc1a9482a
Added to database: 06/25/2026, 23:46:08 UTC
Last enriched: 07/03/2026, 22:21:17 UTC
Last updated: 08/09/2026, 12:41:08 UTC
Views: 72
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.