{"id":"CVE-2026-49875","summary":"Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointReferenceUtils","details":"Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) \nexternal entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.","modified":"2026-07-16T03:31:15.199010149Z","published":"2026-06-12T08:54:50.103Z","database_specific":{"unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"4.2.0"},{"fixed":"4.2.2"},{"fixed":"4.1.7"}]}],"cna_assigner":"apache","cwe_ids":["CWE-611"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49875.json"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/06/11/2"},{"type":"WEB","url":"https://repo.maven.apache.org/maven2"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49875.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:36839"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37390"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-49875"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49875.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/3kb9w5bg90xcp06fccoz9k3gpsvyy79o"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49875"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2488309"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/cxf","events":[{"introduced":"0"},{"fixed":"82e9f60f994a7fad2d89f3c94e9090a4a8990c70"},{"introduced":"04ccbfd709eef8f4af53d6237514fbe9db7ea81f"},{"fixed":"d2b2776cd44a8d2f391194d90f50ce7b3d61a1f6"}],"database_specific":{"cpe":"cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"4.1.7"},{"introduced":"4.2.0"},{"fixed":"4.2.2"}],"source":"CPE_RANGE"}}],"versions":["cxf-4.1.6","cxf-4.2.1","cxf-4.1.5","cxf-4.2.0","cxf-4.1.4","cxf-4.1.3","cxf-4.1.2","cxf-4.1.1","cxf-4.1.0","cxf-4.0.4","cxf-4.0.3","cxf-4.0.2","cxf-4.0.1","cxf-4.0.0","cxf-3.5.0","cxf-3.4.1","cxf-3.4.0","cxf-3.3.3","cxf-3.3.2","cxf-3.3.1","cxf-3.3.0","cxf-3.2.5","cxf-3.2.4","cxf-3.2.3","cxf-3.2.2","cxf-3.2.1","cxf-3.2.0","cxf-3.1.4","cxf-3.1.3","cxf-3.1.2","cxf-3.1.1","cxf-3.1.0","cxf-3.0.0","cxf-3.0.0-milestone2","cxf-2.7.2","cxf-2.7.1","cxf-2.7.0","cxf-2.6.1","cxf-2.6.0","cxf-2.5.1","cxf-2.5.0","cxf-2.4.0","cxf-2.3.0","cxf-2.2.2","cxf-2.2.1","cxf-2.2","cxf-2.1.2","cxf-2.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49875.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}