{"id":"GHSA-fvfq-q238-j7j3","summary":"WSO2 Carbon Mediation vulnerable to XML External Entity (XXE) attacks","details":"An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses user-supplied XML without applying sufficient restrictions, allowing resolution of external entities.\n\nA successful attack could enable a remote, unauthenticated attacker to read sensitive files from the server's filesystem or perform denial-of-service (DoS) attacks that render affected services unavailable.","aliases":["CVE-2025-10713"],"modified":"2026-09-10T03:50:30.978709545Z","published":"2025-11-05T18:31:31Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-11-06T15:12:30Z","nvd_published_at":"2025-11-05T18:15:32Z","cwe_ids":["CWE-611"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-10713"},{"type":"WEB","url":"https://github.com/wso2/carbon-mediation/pull/1784"},{"type":"WEB","url":"https://github.com/wso2/carbon-mediation/commit/b995b2f1db96a4697791f0202cc8713f15640fd5"},{"type":"PACKAGE","url":"https://github.com/wso2/carbon-mediation"},{"type":"WEB","url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4505"}],"affected":[{"package":{"name":"org.wso2.carbon.mediation:org.wso2.carbon.localentry","ecosystem":"Maven","purl":"pkg:maven/org.wso2.carbon.mediation/org.wso2.carbon.localentry"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.6.100","4.6.101","4.6.102","4.6.103","4.6.104","4.6.105","4.6.106","4.6.107","4.6.108","4.6.109","4.6.110","4.6.111","4.6.113","4.6.114","4.6.115","4.6.116","4.6.137","4.6.138","4.6.139","4.6.140","4.6.141","4.6.142","4.6.143","4.6.144","4.6.145","4.6.146","4.6.147","4.6.148","4.6.149","4.6.150","4.6.151","4.6.26","4.6.27","4.6.28","4.6.29","4.6.30","4.6.31","4.6.32","4.6.33","4.6.34","4.6.35","4.6.36","4.6.37","4.6.38","4.6.39","4.6.40","4.6.41","4.6.42","4.6.43","4.6.44","4.6.45","4.6.46","4.6.47","4.6.48","4.6.49","4.6.51","4.6.52","4.6.53","4.6.54","4.6.55","4.6.56","4.6.57","4.6.58","4.6.59","4.6.60","4.6.61","4.6.62","4.6.63","4.6.64","4.6.65","4.6.66","4.6.67","4.6.68","4.6.69","4.6.70","4.6.71","4.6.72","4.6.73","4.6.74","4.6.75","4.6.76","4.6.77","4.6.78","4.6.79","4.6.80","4.6.81","4.6.82","4.6.83","4.6.84","4.6.85","4.6.86","4.6.87","4.6.88","4.6.89","4.6.90","4.6.91","4.6.92","4.6.93","4.6.94","4.6.95","4.6.96","4.6.97","4.6.98","4.6.99","4.7.100","4.7.101","4.7.102","4.7.103","4.7.104","4.7.105","4.7.106","4.7.107","4.7.108","4.7.109","4.7.110","4.7.111","4.7.112","4.7.113","4.7.114","4.7.115","4.7.116","4.7.117","4.7.118","4.7.119","4.7.120","4.7.121","4.7.122","4.7.137","4.7.138","4.7.139","4.7.140","4.7.141","4.7.142","4.7.143","4.7.144","4.7.145","4.7.146","4.7.147","4.7.148","4.7.159","4.7.16","4.7.160","4.7.161","4.7.162","4.7.163","4.7.164","4.7.165","4.7.166","4.7.167","4.7.168","4.7.17","4.7.170","4.7.171","4.7.172","4.7.173","4.7.174","4.7.175","4.7.176","4.7.177","4.7.18","4.7.19","4.7.190","4.7.191","4.7.20","4.7.200","4.7.205","4.7.206","4.7.207","4.7.208","4.7.209","4.7.21","4.7.214","4.7.215","4.7.217","4.7.218","4.7.219","4.7.22","4.7.224","4.7.23","4.7.268","4.7.269","4.7.30","4.7.34","4.7.35","4.7.36","4.7.37","4.7.38","4.7.39","4.7.41","4.7.42","4.7.43","4.7.44","4.7.45","4.7.46","4.7.47","4.7.48","4.7.49","4.7.50","4.7.51","4.7.52","4.7.53","4.7.54","4.7.55","4.7.56","4.7.57","4.7.58","4.7.59","4.7.60","4.7.61","4.7.62","4.7.63","4.7.64","4.7.65","4.7.66","4.7.67","4.7.68","4.7.69","4.7.70","4.7.72","4.7.74","4.7.75","4.7.76","4.7.77","4.7.78","4.7.79","4.7.80","4.7.81","4.7.82","4.7.83","4.7.84","4.7.85","4.7.86","4.7.87","4.7.88","4.7.89","4.7.90","4.7.91","4.7.92","4.7.93","4.7.94","4.7.95","4.7.96","4.7.97","4.7.98","4.7.99","4.8.0","4.8.1","4.8.10","4.8.11","4.8.12","4.8.13","4.8.14","4.8.15","4.8.16","4.8.17","4.8.18","4.8.19","4.8.2","4.8.20","4.8.21","4.8.22","4.8.3","4.8.4","4.8.5","4.8.6","4.8.7","4.8.8","4.8.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-fvfq-q238-j7j3/GHSA-fvfq-q238-j7j3.json","last_known_affected_version_range":"\u003c 4.7.259"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H"}]}