Threats Tagged 'cwe-611'
View all threats tagged with 'cwe-611'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-611'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-44018: CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) in docling-project doclingCVE-2026-44018 0 Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked security controls. An attacker could craft malicious METS-GBS archives that, when processed, could read sensitive files, exhaust system resources, or cause application crashes. This vulnerability is fixed in 2.91.0. Join the discussion | CVE Database V5 | 06/26/2026, 15:40:42 UTC Added: 06/26/2026, 16:06:55 UTC |
CVE-2026-57234: CWE-178: Improper Handling of Case Sensitivity in sparklemotion nokogiriCVE-2026-57234 0 Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse option, which Nokogiri turns on by default for Nokogiri::XML::Schema (see CVE-2020-26247), was not correctly enforced on the JRuby implementation. As a result, a schema parsed with default options could still cause external resources to be fetched over the network, potentially enabling SSRF or XXE attacks. This vulnerability is fixed in 1.19.4. Join the discussion | CVE Database V5 | 06/25/2026, 14:30:20 UTC Added: 06/25/2026, 14:46:08 UTC |
CVE-2026-6653: CWE-416 Use after free in GNOME libxml2CVE-2026-6653 0 Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling. Join the discussion | CVE Database V5 | 06/22/2026, 12:40:31 UTC Added: 06/22/2026, 13:54:18 UTC |
CVE-2026-48981: CWE-611: Improper Restriction of XML External Entity Reference in mcdope pam_usbCVE-2026-48981 0 pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, pam_usb calls xmlReadFile() with flags=0 when loading the configuration file, allowing libxml2 to process external entity references (XXE), potentially making outbound network connections or local file reads at XML parse time from the context of the authenticating process. The vulnerability requires the configuration file to contain crafted XML entity references. Since pam_usb.conf is root-owned, direct exploitation requires prior write access to the config, but the defence-in-depth impact is significant given that pam_usb.so runs in setuid contexts (sudo, su). This issue has been fixed in version 0.9.2. Join the discussion | CVE Database V5 | 06/18/2026, 18:55:58 UTC Added: 06/18/2026, 19:51:23 UTC |
CVE-2025-58175: CWE-20: Improper Input Validation in geoserver org.geoserver.web:gs-web-appCVE-2025-58175 0 GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a GeoServer that uses `ENTITY_RESOLUTION_ALLOWLIST` may allow attacker to perform unauthenticated Server-Side Request Forgery (SSRF). This vulnerability requires that GeoServer is set up to use a proxy base URL and the `ENTITY_RESOLUTION_ALLOWLIST` (default since 2.25.0). Versions 2.26.4 and 2.27.3 contain a fix. GeoServer installations are only affected by this vulnerability if they use a proxy base URL that does not contain a URL path or end with a slash. If the proxy base URL does not contain a path, adding a slash to the end of the URL will mitigate this vulnerability. Join the discussion | CVE Database V5 | 06/18/2026, 14:31:19 UTC Added: 06/18/2026, 15:20:12 UTC |
CVE-2026-49875: CWE-611 Improper Restriction of XML External Entity Reference in Apache Software Foundation Apache CXFCVE-2026-49875 0 Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue. Join the discussion | CVE Database V5 | 06/12/2026, 08:54:50 UTC Added: 06/12/2026, 09:54:35 UTC |
CVE-2026-40998: CWE-611: Improper Restriction of XML External Entity Reference in Spring Spring Web ServicesCVE-2026-40998 0 Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser configuration. Applications that evaluate XPath against untrusted XML payloads could therefore be exposed to XML External Entity (XXE) style attacks. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8. Join the discussion | CVE Database V5 | 06/11/2026, 05:04:12 UTC Added: 06/11/2026, 06:46:18 UTC |
CVE-2026-40991: CWE-611: Improper Restriction of XML External Entity Reference in Spring Spring REST DocsCVE-2026-40991 0 When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a malicious API can perform an XXE injection attack when the documentation-generating tests are next executed. Affected versions: Spring REST Docs 4.0.0; 3.0.0 through 3.0.5; 2.0.0.RELEASE through 2.0.8.RELEASE. Join the discussion | CVE Database V5 | 06/09/2026, 23:46:33 UTC Added: 06/09/2026, 23:55:46 UTC |
CVE-2026-47960: Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) in Adobe ColdFusionCVE-2026-47960 0 Adobe ColdFusion versions 2023.0.0 through 2023.19 and 2025.0.0 through 2025.8 are affected by an XML External Entity (XXE) vulnerability (CWE-611). This vulnerability allows an attacker to read arbitrary files on the system by exploiting improper restriction of XML external entity references. Exploitation requires user interaction, specifically that a victim opens a malicious file. The vulnerability impacts confidentiality but does not affect integrity or availability. Join the discussion | CVE Database V5 | 06/09/2026, 20:33:37 UTC Added: 06/09/2026, 21:10:50 UTC |
CVE-2026-8045: CWE-611 Improper restriction of XML external entity reference in Schneider Electric EcoStruxure™ IT Data Center ExpertCVE-2026-8045 0 CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints. Join the discussion | GCVE Database | 06/09/2026, 14:41:56 UTC Added: 06/09/2026, 10:22:54 UTC |
Showing 1 to 10 of 13 results