Description
Improper Restriction of XML External Entity Reference in the XSLT support extension (camel-quarkus-support-xalan) in Apache Camel Quarkus from 3.2.0 before 3.33.3 and from 3.34.0 before 3.40.0 on all platforms allows an attacker who supplies the XML document being transformed to read local files or issue requests to internal network locations via an external entity declaration in that document.

The extension supplies its own Xalan-backed TransformerFactory to the xslt component and registers it as the JAXP default. Xalan-J 2.7.x predates JAXP 1.5 and does not honour javax.xml.XMLConstants.ACCESS_EXTERNAL_DTD or ACCESS_EXTERNAL_STYLESHEET, so the external access restrictions Apache Camel applies to the TransformerFactory it creates were not in effect. On the xslt component path this affects message bodies that reach the transformer already as a javax.xml.transform.Source; bodies of other types are converted to a SAXSource by Apache Camel with external entities and external DTD loading disabled, and are not affected. Because the factory is also the JAXP default, other code in the application obtaining one through TransformerFactory.newInstance() loses the same restrictions without error.

Applications are affected if they use any of camel-quarkus-xslt, camel-quarkus-xslt-saxon, camel-quarkus-tika or camel-quarkus-xmlsecurity, each of which brings the XSLT support extension onto the classpath. For all but camel-quarkus-xslt, the exposure is limited to the JAXP default factory, since those extensions do not perform XSLT transformations themselves.

Users are recommended to upgrade to version 3.33.3 or 3.40.0, which fixes this issue.
Published: 2026-10-01
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Information Disclosure via XML External Entity in XSLT
Action: Immediate Patch
AI Analysis

Impact

The vulnerability stems from an improper restriction of XML External Entity (XEE) references in the XSLT support extension of Apache Camel Quarkus. By supplying an XML document that contains external entity declarations, an attacker can cause the Xalan‑backed TransformerFactory to read local files or send requests to internal network locations. This flaw allows sensitive data leakage from the target system without needing to execute code outside the application context. The weakness is classified as CWE‑611, indicating that external DTD or stylesheet access controls are not correctly enforced.

Affected Systems

The issue affects applications that include any of the following Camel Quarkus extensions: camel‑quarkus‑xslt, camel‑quarkus‑xslt‑saxon, camel‑quarkus‑tika, camel‑quarkus‑xmlsecurity, and specifically the Xalan‑based XSLT support extension camel‑quarkus‑support‑xalan. All platforms running Apache Camel Quarkus version 3.2.0 up to but not including 3.33.3, and versions 3.34.0 up to but not including 3.40.0 are vulnerable.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity, and the EPSS score is not available, with the vulnerability not listed in CISA KEV. Based on the description, it is inferred that an attacker who can supply a crafted XML document to the application—such as through a remote interface that accepts XML—could trigger the flaw. Because the vulnerability can be induced by providing crafted XML to any component that performs XSLT transformations, it can potentially be exploited remotely over a network connection that offers XML input. The vulnerability is active in the JAXP default factory, meaning that any application code invoking TransformerFactory.newInstance() in the same runtime will inherit the same unprotected access rights, expanding the attack surface.

Generated by OpenCVE AI on October 1, 2026 at 14:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Camel Quarkus to version 3.33.3 or 3.40.0, which removes the unprotected Xalan TransformerFactory.
  • If an upgrade is not feasible immediately, remove or disable the camel‑quarkus‑support‑xalan extension and any other XSLT support extensions that register the default factory.
  • Configure your application to use a secure, vendor‑supported TransformerFactory or explicitly set the XMLConstants.ACCESS_EXTERNAL_DTD and ACCESS_EXTERNAL_STYLESHEET properties before performing transformations.

Generated by OpenCVE AI on October 1, 2026 at 14:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
References

Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Improper Restriction of XML External Entity Reference in the XSLT support extension (camel-quarkus-support-xalan) in Apache Camel Quarkus from 3.2.0 before 3.33.3 and from 3.34.0 before 3.40.0 on all platforms allows an attacker who supplies the XML document being transformed to read local files or issue requests to internal network locations via an external entity declaration in that document. The extension supplies its own Xalan-backed TransformerFactory to the xslt component and registers it as the JAXP default. Xalan-J 2.7.x predates JAXP 1.5 and does not honour javax.xml.XMLConstants.ACCESS_EXTERNAL_DTD or ACCESS_EXTERNAL_STYLESHEET, so the external access restrictions Apache Camel applies to the TransformerFactory it creates were not in effect. On the xslt component path this affects message bodies that reach the transformer already as a javax.xml.transform.Source; bodies of other types are converted to a SAXSource by Apache Camel with external entities and external DTD loading disabled, and are not affected. Because the factory is also the JAXP default, other code in the application obtaining one through TransformerFactory.newInstance() loses the same restrictions without error. Applications are affected if they use any of camel-quarkus-xslt, camel-quarkus-xslt-saxon, camel-quarkus-tika or camel-quarkus-xmlsecurity, each of which brings the XSLT support extension onto the classpath. For all but camel-quarkus-xslt, the exposure is limited to the JAXP default factory, since those extensions do not perform XSLT transformations themselves. Users are recommended to upgrade to version 3.33.3 or 3.40.0, which fixes this issue.
Title Apache Camel Quarkus: Camel Quarkus: Forced Xalan TransformerFactory drops upstream external-DTD/stylesheet hardening
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-01T14:56:28.388Z

Reserved: 2026-09-10T07:56:46.005Z

Link: CVE-2026-88789

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:28.917

Modified: 2026-10-01T15:17:32.640

Link: CVE-2026-88789

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:45:10Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference