Eclipse Foundation · Eclipse Rdf4J · CVE-2026-15803
**Name of the Vulnerable Software and Affected Versions**
Eclipse RDF4J versions prior to 5.3.2
**Description**
Several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF data or query results. This allows the use of DOCTYPE declarations, external entity references, and external DTD loading. XXE is a type of attack where an XML parser improperly handles external entity references within an XML document, potentially allowing access to unauthorized files or internal network resources.
**Recommendations**
Update to version 5.3.2.