PT-2026-71136 · Eclipse Foundation+1 · Eclipse Rdf4J+1
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Eclipse RDF4J versions prior to 5.3.2
Description
Several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF data or query results. This allows the use of DOCTYPE declarations, external entity references, and external DTD loading. XXE is a type of attack where an XML parser improperly handles external entity references within an XML document, potentially allowing access to unauthorized files or internal network resources.
Recommendations
Update to version 5.3.2.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eclipse Rdf4J
Rdf4J