PT-2026-103830 · Apache · Apache Camel Quarkus
CVE-2026-88789
·
Published
2026-10-01
·
Updated
2026-10-01
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Camel Quarkus versions 3.2.0 through 3.33.2
Apache Camel Quarkus versions 3.34.0 through 3.39.9
Description
Improper restriction of XML External Entity (XXE) references in the XSLT support extension
camel-quarkus-support-xalan allows an attacker providing a transformed XML document to read local files or send requests to internal network locations via external entity declarations. The extension uses a Xalan-backed TransformerFactory that does not honor javax.xml.XMLConstants.ACCESS EXTERNAL DTD or ACCESS EXTERNAL STYLESHEET, rendering Apache Camel's external access restrictions ineffective. This specifically affects message bodies that reach the transformer as a javax.xml.transform.Source. Additionally, because this factory is registered as the JAXP default, other application code using TransformerFactory.newInstance() also loses these restrictions. Applications are affected if they utilize camel-quarkus-xslt, camel-quarkus-xslt-saxon, camel-quarkus-tika, or camel-quarkus-xmlsecurity.Recommendations
Upgrade Apache Camel Quarkus versions 3.2.0 through 3.33.2 to version 3.33.3.
Upgrade Apache Camel Quarkus versions 3.34.0 through 3.39.9 to version 3.40.0.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Camel Quarkus