{"id":"GHSA-6fhj-vr9j-g45r","summary":"CycloneDX Core (Java): BOM validation is vulnerable to XML External Entity injection ","details":"### Impact\n\nThe XML [`Validator`](https://docs.oracle.com/javase/8/docs/api/javax/xml/validation/Validator.html) used by cyclonedx-core-java was not configured securely, making the library vulnerable to XML External Entity (XXE) injection.\n\nThe fix for GHSA-683x-4444-jxh8 / CVE-2024-38374 has been incomplete in that it only fixed *parsing* of XML BOMs, but not *validation*.\n\n### Patches\n\nThe vulnerability has been fixed in cyclonedx-core-java version 11.0.1.\n\n### Workarounds\n\nIf feasible, applications can reject XML documents before handing them to cyclonedx-core-java for validation.\nThis may be an option if incoming CycloneDX BOMs are known to be in JSON format.\n\n### References\n\n* The issue was introduced via https://github.com/CycloneDX/cyclonedx-core-java/commit/162aa594f347b3f612fe0a45071693c3cd398ce9\n* The issue was fixed via https://github.com/CycloneDX/cyclonedx-core-java/pull/737\n* https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#schemafactory","aliases":["CVE-2025-64518"],"modified":"2026-09-10T03:50:30.718763770Z","published":"2025-11-10T21:04:03Z","database_specific":{"github_reviewed_at":"2025-11-10T21:04:03Z","nvd_published_at":"2025-11-10T22:15:40Z","cwe_ids":["CWE-611"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/CycloneDX/cyclonedx-core-java/security/advisories/GHSA-6fhj-vr9j-g45r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64518"},{"type":"WEB","url":"https://github.com/CycloneDX/cyclonedx-core-java/pull/737"},{"type":"WEB","url":"https://github.com/CycloneDX/cyclonedx-core-java/commit/162aa594f347b3f612fe0a45071693c3cd398ce9"},{"type":"WEB","url":"https://github.com/CycloneDX/cyclonedx-core-java/commit/af0ec75c93c03f93733a070c5132554490af5314"},{"type":"WEB","url":"https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#schemafactory"},{"type":"PACKAGE","url":"https://github.com/CycloneDX/cyclonedx-core-java"}],"affected":[{"package":{"name":"org.cyclonedx:cyclonedx-core-java","ecosystem":"Maven","purl":"pkg:maven/org.cyclonedx/cyclonedx-core-java"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.0"},{"fixed":"11.0.1"}]}],"versions":["10.0.0","10.1.0","10.2.1","11.0.0","2.1.0","2.1.1","2.5.0","2.5.1","2.6.0","2.6.1","2.6.2","2.6.3","2.6.4","2.6.5","2.7.0","3.0.0","3.0.1","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","4.0.0","4.0.1","4.0.2","4.0.3","4.1.0","4.1.1","4.1.2","5.0.0","5.0.1","5.0.2","5.0.3","5.0.4","5.0.5","6.0.0","7.0.0","7.1.0","7.1.1","7.1.2","7.1.3","7.1.4","7.1.5","7.1.6","7.2.0","7.2.1","7.3.0","7.3.1","7.3.2","8.0.0","8.0.1","8.0.2","8.0.3","9.0.0","9.0.1","9.0.2","9.0.3","9.0.4","9.0.5","9.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-6fhj-vr9j-g45r/GHSA-6fhj-vr9j-g45r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}