Impact
This vulnerability is an XML External Entity (XXE) flaw in libpvestorage-perl version 9.1.1 and libpve-storage-perl version 8.3.7. The description does not explicitly state the possible outcomes of processing a malicious XML document, but XXE flaws typically enable attackers to read arbitrary files or trigger denial of service. These consequences are inferred from common XXE behaviour rather than directly asserted.
Affected Systems
Systems that use libpvestorage-perl 9.1.1 or libpve-storage-perl 8.3.7 are vulnerable. No additional vendor or product information is provided.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% suggests exploitation is infrequent at present. The vulnerability is not listed in the CISA KEV catalogue. Attackers would need access to an application's XML input handling; the description implies that a crafted XML could trigger external entity resolution. The lack of an official exploitation example indicates that potential impacts such as file disclosure or denial of service are typical for XXE but are not confirmed for this specific case.
OpenCVE Enrichment