PT-2026-103830 · Apache · Apache Camel Quarkus

CVE-2026-88789

·

Published

2026-10-01

·

Updated

2026-10-01

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Camel Quarkus versions 3.2.0 through 3.33.2 Apache Camel Quarkus versions 3.34.0 through 3.39.9
Description Improper restriction of XML External Entity (XXE) references in the XSLT support extension camel-quarkus-support-xalan allows an attacker providing a transformed XML document to read local files or send requests to internal network locations via external entity declarations. The extension uses a Xalan-backed TransformerFactory that does not honor javax.xml.XMLConstants.ACCESS EXTERNAL DTD or ACCESS EXTERNAL STYLESHEET, rendering Apache Camel's external access restrictions ineffective. This specifically affects message bodies that reach the transformer as a javax.xml.transform.Source. Additionally, because this factory is registered as the JAXP default, other application code using TransformerFactory.newInstance() also loses these restrictions. Applications are affected if they utilize camel-quarkus-xslt, camel-quarkus-xslt-saxon, camel-quarkus-tika, or camel-quarkus-xmlsecurity.
Recommendations Upgrade Apache Camel Quarkus versions 3.2.0 through 3.33.2 to version 3.33.3. Upgrade Apache Camel Quarkus versions 3.34.0 through 3.39.9 to version 3.40.0.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-88789

Affected Products

Apache Camel Quarkus