PT-2026-60771 · Proxmox · Libpve-Storage-Perl+2

CVE-2026-51080

·

Published

2026-07-17

·

Updated

2026-09-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libpvestorage-perl version 9.1.1 libpve-storage-perl version 8.3.7
Description An XML External Entity (XXE) flaw exists in the storage Perl components of Proxmox VE. This issue stems from insecure XML parsing caused by improper parser configuration and input validation, which allows external entity resolution. An attacker can exploit this by providing crafted XML to any reachable code path that parses attacker-influenced XML, such as API or UI-driven operations, import/metadata handling, or integrations. Successful exploitation can lead to the disclosure of sensitive local files and potentially enable Server-Side Request Forgery (SSRF), which allows an attacker to make requests from the server to internal network resources.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-51080

Affected Products

Proxmox Ve
Libpve-Storage-Perl
Libpvestorage-Perl