{"id":"GHSA-h94w-8qhg-3xmc","summary":"WSO2 API Manager XML External Entity (XXE) vulnerability","details":"An XML External Entity (XXE) vulnerability exists in the gateway component of WSO2 API Manager due to insufficient validation of XML input in crafted URL paths. User-supplied XML is parsed without appropriate restrictions, enabling external entity resolution.\n\nThis vulnerability can be exploited by an unauthenticated remote attacker to read files from the server’s filesystem or perform denial-of-service (DoS) attacks.\n\n  *  On systems running JDK 7 or early JDK 8, full file contents may be exposed.\n\n  *  On later versions of JDK 8 and newer, only the first line of a file may be read, due to improvements in XML parser behavior.\n\n  *  DoS attacks such as \"Billion Laughs\" payloads can cause service disruption.","aliases":["CVE-2025-2905"],"modified":"2025-05-05T20:42:09.307666Z","published":"2025-05-05T09:31:09Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-05-05T19:58:08Z","nvd_published_at":"2025-05-05T09:15:15Z","cwe_ids":["CWE-611"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-2905"},{"type":"PACKAGE","url":"https://github.com/wso2/product-apim"},{"type":"WEB","url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-3993"}],"affected":[{"package":{"name":"org.wso2.am:am-distribution-parent","ecosystem":"Maven","purl":"pkg:maven/org.wso2.am/am-distribution-parent"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.0"}]}],"versions":["1.10.0","2.0.0","2.1.0-alpha"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-h94w-8qhg-3xmc/GHSA-h94w-8qhg-3xmc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}