Description
libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.
Published: 2026-07-17
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an XML External Entity (XXE) flaw in libpvestorage-perl version 9.1.1 and libpve-storage-perl version 8.3.7. The description does not explicitly state the possible outcomes of processing a malicious XML document, but XXE flaws typically enable attackers to read arbitrary files or trigger denial of service. These consequences are inferred from common XXE behaviour rather than directly asserted.

Affected Systems

Systems that use libpvestorage-perl 9.1.1 or libpve-storage-perl 8.3.7 are vulnerable. No additional vendor or product information is provided.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% suggests exploitation is infrequent at present. The vulnerability is not listed in the CISA KEV catalogue. Attackers would need access to an application's XML input handling; the description implies that a crafted XML could trigger external entity resolution. The lack of an official exploitation example indicates that potential impacts such as file disclosure or denial of service are typical for XXE but are not confirmed for this specific case.

Generated by OpenCVE AI on August 4, 2026 at 18:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch that updates libpvestorage-perl to a version that resolves the CWE‑611 XML External Entity parsing flaw.
  • Apply the vendor‑issued patch that updates libpve‑storage‑perl to a version that resolves the CWE‑611 XML External Entity parsing flaw.
  • Configure the XML parser used by the application to disable external entity resolution and DTD processing.
  • Monitor application logs for abnormal XML processing attempts and investigate any anomalies.

Generated by OpenCVE AI on August 4, 2026 at 18:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title XML External Entity (XXE) Vulnerability in libpvestorage-perl and libpve-storage-perl

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Proxmox
Proxmox libpve-storage-perl
Proxmox libpvestorage-perl
Vendors & Products Proxmox
Proxmox libpve-storage-perl
Proxmox libpvestorage-perl

Sat, 25 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title XML External Entity Vulnerability in libpvestorage-perl and libpve-storage-perl

Wed, 22 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title XML External Entity Vulnerability in libpvestorage-perl and libpve-storage-perl

Fri, 17 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-611
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Description libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.
References

Subscriptions

Proxmox Libpve-storage-perl Libpvestorage-perl
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-17T16:55:36.699Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-51080

cve-icon Vulnrichment

Updated: 2026-07-17T16:55:27.606Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T18:45:12Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference