PT-2026-60771 · Proxmox · Libpve-Storage-Perl+2
CVE-2026-51080
·
Published
2026-07-17
·
Updated
2026-09-02
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
libpvestorage-perl version 9.1.1
libpve-storage-perl version 8.3.7
Description
An XML External Entity (XXE) flaw exists in the storage Perl components of Proxmox VE. This issue stems from insecure XML parsing caused by improper parser configuration and input validation, which allows external entity resolution. An attacker can exploit this by providing crafted XML to any reachable code path that parses attacker-influenced XML, such as API or UI-driven operations, import/metadata handling, or integrations. Successful exploitation can lead to the disclosure of sensitive local files and potentially enable Server-Side Request Forgery (SSRF), which allows an attacker to make requests from the server to internal network resources.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Proxmox Ve
Libpve-Storage-Perl
Libpvestorage-Perl