PT-2026-71136 · Eclipse Foundation+1 · Eclipse Rdf4J+1

·

CVE-2026-15803

·

Published

2026-08-12

·

Updated

2026-08-12

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Eclipse RDF4J versions prior to 5.3.2
Description Several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF data or query results. This allows the use of DOCTYPE declarations, external entity references, and external DTD loading. XXE is a type of attack where an XML parser improperly handles external entity references within an XML document, potentially allowing access to unauthorized files or internal network resources.
Recommendations Update to version 5.3.2.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15803

Affected Products

Eclipse Rdf4J
Rdf4J