Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.3%top 80%

CVE-2026-28809: CWE-611 Improper Restriction of XML External Entity Reference in dropbox esaml

0
Medium
VulnerabilityCVE-2026-28809cvecve-2026-28809cwe-611
Published: 03/23/2026 (03/23/2026, 10:09:29 UTC)
Source: CVE Database V5
Vendor/Project: dropbox
Product: esaml

Description

XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local files and incorporate their contents into processed SAML documents, and potentially perform SSRF via crafted SAML messages. esaml parses attacker-controlled SAML messages using xmerl_scan:string/2 before signature verification without disabling XML entity expansion. On Erlang/OTP versions before 27, Xmerl allows entities by default, enabling pre-signature XXE attacks. An attacker can cause the host to read local files (e.g., Kubernetes-mounted secrets) into the SAML document. If the attacker is not a trusted SAML SP, signature verification will fail and the document is discarded, but file contents may still be exposed through logs or error messages. This issue affects all versions of esaml, including forks by arekinath, handnot2, and dropbox. Users running on Erlang/OTP 27 or later are not affected due to Xmerl defaulting to entities disabled.

CVSS v4.0

Score 6.3medium

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
Low
Vuln. Integrity
None
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected software

GitHub Actionsmore threats →ai
jump-app/esaml
pkg:github/jump-app/esaml
Affected versions
*

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/24/2026, 21:33:55 UTC

Technical Analysis

The esaml library and its forks, including dropbox esaml, are vulnerable to an XML External Entity (XXE) attack due to parsing SAML messages with xmerl_scan:string/2 before signature verification without disabling XML entity expansion. On Erlang/OTP versions before 27, xmerl allows XML entities by default, enabling an attacker to craft malicious SAML messages that cause the host to read local files and incorporate their contents into the SAML document. If the attacker is not a trusted SAML service provider, signature verification fails and the document is discarded, but sensitive file contents may still be exposed through logs or error messages. This vulnerability affects all versions of esaml on Erlang/OTP versions prior to 27. Erlang/OTP 27 and later are not affected due to a change in xmerl default behavior disabling entity expansion.

Potential Impact

An attacker can exploit this vulnerability to read local files on the host system by embedding XML external entities in crafted SAML messages. This can lead to disclosure of sensitive information such as Kubernetes-mounted secrets. Although signature verification prevents acceptance of messages from untrusted sources, sensitive data may still be exposed in logs or error messages. There is also potential for server-side request forgery (SSRF) via crafted SAML messages. The vulnerability has a CVSS 4.0 score of 6.3 (medium severity).

Mitigation Recommendations

No official patch or fix is currently available for esaml itself. However, users running esaml on Erlang/OTP version 27 or later are not affected due to the default disabling of XML entity expansion in xmerl. Therefore, upgrading the Erlang/OTP runtime to version 27 or later effectively mitigates this vulnerability. Users should verify their Erlang/OTP version and consider upgrading accordingly. Additionally, avoid processing untrusted SAML messages before signature verification or disable XML entity expansion if possible. Patch status is not yet confirmed for esaml; check vendor advisories for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
EEF
Date Reserved
2026-03-03T14:40:00.590Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 69c119e0f4197a8e3b3cb44c

Added to database: 03/23/2026, 10:45:52 UTC

Last enriched: 07/24/2026, 21:33:55 UTC

Last updated: 07/31/2026, 19:22:58 UTC

Views: 187

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses