Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-12975

Опубликовано: 25 июн. 2026
Источник: nvd
CVSS3: 8.5
EPSS Низкий

Описание

A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without enabling secure processing features or disabling external entity resolution. An attacker with artifact-write permission (or unauthenticated when the registry runs with default configuration) can upload a crafted XML document to trigger blind server-side request forgery (SSRF) via external DTD/entity fetch, or cause denial of service via entity expansion.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:build_of_apicurio_registry:*:*:*:*:*:*:*:*
Версия от 3.0 (включая) до 3.2 (включая)

EPSS

Процентиль: 14%
0.00233
Низкий

8.5 High

CVSS3

Дефекты

CWE-611
CWE-611

Связанные уязвимости

CVSS3: 8.5
redhat
2 месяца назад

A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without enabling secure processing features or disabling external entity resolution. An attacker with artifact-write permission (or unauthenticated when the registry runs with default configuration) can upload a crafted XML document to trigger blind server-side request forgery (SSRF) via external DTD/entity fetch, or cause denial of service via entity expansion.

CVSS3: 8.5
github
около 2 месяцев назад

A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without enabling secure processing features or disabling external entity resolution. An attacker with artifact-write permission (or unauthenticated when the registry runs with default configuration) can upload a crafted XML document to trigger blind server-side request forgery (SSRF) via external DTD/entity fetch, or cause denial of service via entity expansion.

EPSS

Процентиль: 14%
0.00233
Низкий

8.5 High

CVSS3

Дефекты

CWE-611
CWE-611