CVE-2026-28809: CWE-611 Improper Restriction of XML External Entity Reference in dropbox esaml
XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local files and incorporate their contents into processed SAML documents, and potentially perform SSRF via crafted SAML messages. esaml parses attacker-controlled SAML messages using xmerl_scan:string/2 before signature verification without disabling XML entity expansion. On Erlang/OTP versions before 27, Xmerl allows entities by default, enabling pre-signature XXE attacks. An attacker can cause the host to read local files (e.g., Kubernetes-mounted secrets) into the SAML document. If the attacker is not a trusted SAML SP, signature verification will fail and the document is discarded, but file contents may still be exposed through logs or error messages. This issue affects all versions of esaml, including forks by arekinath, handnot2, and dropbox. Users running on Erlang/OTP 27 or later are not affected due to Xmerl defaulting to entities disabled.
AI Analysis
Technical Summary
The esaml library and its forks, including dropbox esaml, are vulnerable to an XML External Entity (XXE) attack due to parsing SAML messages with xmerl_scan:string/2 before signature verification without disabling XML entity expansion. On Erlang/OTP versions before 27, xmerl allows XML entities by default, enabling an attacker to craft malicious SAML messages that cause the host to read local files and incorporate their contents into the SAML document. If the attacker is not a trusted SAML service provider, signature verification fails and the document is discarded, but sensitive file contents may still be exposed through logs or error messages. This vulnerability affects all versions of esaml on Erlang/OTP versions prior to 27. Erlang/OTP 27 and later are not affected due to a change in xmerl default behavior disabling entity expansion.
Potential Impact
An attacker can exploit this vulnerability to read local files on the host system by embedding XML external entities in crafted SAML messages. This can lead to disclosure of sensitive information such as Kubernetes-mounted secrets. Although signature verification prevents acceptance of messages from untrusted sources, sensitive data may still be exposed in logs or error messages. There is also potential for server-side request forgery (SSRF) via crafted SAML messages. The vulnerability has a CVSS 4.0 score of 6.3 (medium severity).
Mitigation Recommendations
No official patch or fix is currently available for esaml itself. However, users running esaml on Erlang/OTP version 27 or later are not affected due to the default disabling of XML entity expansion in xmerl. Therefore, upgrading the Erlang/OTP runtime to version 27 or later effectively mitigates this vulnerability. Users should verify their Erlang/OTP version and consider upgrading accordingly. Additionally, avoid processing untrusted SAML messages before signature verification or disable XML entity expansion if possible. Patch status is not yet confirmed for esaml; check vendor advisories for updates.
CVE-2026-28809: CWE-611 Improper Restriction of XML External Entity Reference in dropbox esaml
Description
XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local files and incorporate their contents into processed SAML documents, and potentially perform SSRF via crafted SAML messages. esaml parses attacker-controlled SAML messages using xmerl_scan:string/2 before signature verification without disabling XML entity expansion. On Erlang/OTP versions before 27, Xmerl allows entities by default, enabling pre-signature XXE attacks. An attacker can cause the host to read local files (e.g., Kubernetes-mounted secrets) into the SAML document. If the attacker is not a trusted SAML SP, signature verification will fail and the document is discarded, but file contents may still be exposed through logs or error messages. This issue affects all versions of esaml, including forks by arekinath, handnot2, and dropbox. Users running on Erlang/OTP 27 or later are not affected due to Xmerl defaulting to entities disabled.
CVSS v4.0
Score 6.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The esaml library and its forks, including dropbox esaml, are vulnerable to an XML External Entity (XXE) attack due to parsing SAML messages with xmerl_scan:string/2 before signature verification without disabling XML entity expansion. On Erlang/OTP versions before 27, xmerl allows XML entities by default, enabling an attacker to craft malicious SAML messages that cause the host to read local files and incorporate their contents into the SAML document. If the attacker is not a trusted SAML service provider, signature verification fails and the document is discarded, but sensitive file contents may still be exposed through logs or error messages. This vulnerability affects all versions of esaml on Erlang/OTP versions prior to 27. Erlang/OTP 27 and later are not affected due to a change in xmerl default behavior disabling entity expansion.
Potential Impact
An attacker can exploit this vulnerability to read local files on the host system by embedding XML external entities in crafted SAML messages. This can lead to disclosure of sensitive information such as Kubernetes-mounted secrets. Although signature verification prevents acceptance of messages from untrusted sources, sensitive data may still be exposed in logs or error messages. There is also potential for server-side request forgery (SSRF) via crafted SAML messages. The vulnerability has a CVSS 4.0 score of 6.3 (medium severity).
Mitigation Recommendations
No official patch or fix is currently available for esaml itself. However, users running esaml on Erlang/OTP version 27 or later are not affected due to the default disabling of XML entity expansion in xmerl. Therefore, upgrading the Erlang/OTP runtime to version 27 or later effectively mitigates this vulnerability. Users should verify their Erlang/OTP version and consider upgrading accordingly. Additionally, avoid processing untrusted SAML messages before signature verification or disable XML entity expansion if possible. Patch status is not yet confirmed for esaml; check vendor advisories for updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- EEF
- Date Reserved
- 2026-03-03T14:40:00.590Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 69c119e0f4197a8e3b3cb44c
Added to database: 03/23/2026, 10:45:52 UTC
Last enriched: 07/24/2026, 21:33:55 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 187
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.