CVE-2026-65432

Improper Restriction of XML External Entity Reference
Affects
Apache CXF
in
Apache CXF
No items found.
Versions
<3.6.12, >=4.0.0 <4.1.8, >=4.2.0 <4.2.3

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Apache CXF is an open-source services framework, maintained by the Apache Software Foundation, for building and consuming web services in Java. It implements the JAX-WS and JAX-RS APIs and supports SOAP, the WS-* standards, RESTful HTTP, and OAuth 2.0 over transports such as HTTP and JMS. Its modules are published as Maven artifacts under org.apache.cxf.

An Improper Restriction of XML External Entity Reference (XXE) vulnerability (CVE-2026-65432) has been identified in the WSDL loading code of the Apache CXF cxf-rt-wsdl module, which allows attackers who can influence a WSDL or XML Schema document imported through <wsdl:import> or <xsd:import> to use XML External Entity (XXE) declarations to read local files from the host or make the server issue requests to internal resources. CXF parses the top-level WSDL through its hardened StaxUtils parser, which disables DTDs and external entities. Imported documents are instead handed to WSDL4J, which does not disable DOCTYPE declarations or external entity resolution.

Per OWASP: An XXE attack occurs when untrusted XML input with a reference to an external entity is processed by a weakly configured XML parser.

This issue affects all versions of Apache CXF before 3.6.12, versions 4.0.0 through 4.1.7, and versions 4.2.0 through 4.2.2, including the End-of-Life 3.5.x line.

Details

Module Info

Vulnerability Info

This High-severity vulnerability is found in the cxf-rt-wsdl package in all versions before 3.6.12, versions 4.0.0 through 4.1.7, and versions 4.2.0 through 4.2.2 of Apache CXF.

When CXF builds a WSDL definition, WSDL4J resolves every <wsdl:import> and <xsd:import> it encounters by calling back into CXF's WSDLLocator. In AbstractWrapperWSDLLocator.getImportInputSource, CXF checks only the URI scheme of the import location and then returns the raw byte or character stream of the imported document to WSDL4J unchanged:

public InputSource getImportInputSource(String parentLocation, String importLocation) {
    // Do a check on the scheme to see if it's anything that could be a security risk
    try {
        URI url = new URI(importLocation);
        if (!(url.getScheme() == null || ALLOWED_SCHEMES.contains(url.getScheme()))) {
            throw new IllegalArgumentException("The " + url.getScheme() + " URI scheme is not allowed");
        }
    } catch (URISyntaxException e) {
        // Just continue here as we might still be able to load it from the filesystem
    }

    InputSource src = parent.getImportInputSource(parentLocation, importLocation);
    lastImport = null;
    if (src == null || (src.getByteStream() == null && src.getCharacterStream() == null)) {
        src = getInputSource(parentLocation, importLocation);
        if (src != null) {
            lastImport = src.getSystemId();
        }
    }
    return src;
}

WSDL4J parses that stream with a DocumentBuilderFactory that has no XXE protections, so a DOCTYPE in the imported document that declares an external entity (for example <!ENTITY xxe SYSTEM "file:///etc/passwd">) is resolved, and its content is expanded into the parsed schema or WSDL. The DOM-element read path in WSDLManagerImpl.getDefinition goes around the locator completely: it passes an empty base URI, so imports referenced from an already-parsed element go straight to WSDL4J's own resolver:

final WSDLReader reader = factory.newWSDLReader();
reader.setFeature("javax.wsdl.verbose", false);
reader.setExtensionRegistry(registry);

final Definition def;

// This is needed to avoid security exceptions when running with a security manager
if (System.getSecurityManager() == null) {
    def = reader.readWSDL("", el);
} else {
    try {
        def = AccessController.doPrivileged(
                (PrivilegedExceptionAction<Definition>) () -> reader.readWSDL("", el));
    } catch (PrivilegedActionException paex) {
        throw new WSDLException(WSDLException.PARSER_ERROR, paex.getMessage(), paex);
    }
}

Any application that loads a WSDL whose imports an attacker can control or influence is exposed. This includes clients built from a remote service WSDL, dynamic clients, and tooling that fetches WSDLs from untrusted locations. The attacker can then read files the JVM can access, or reach internal network resources from the server.

This vulnerability was introduced in 2006 with Apache CXF 2.0-incubator-M1.

Mitigation

Only recent versions of Apache CXF are community-supported. The 3.5.x line was already End-of-Life when this CVE was published and will not receive public updates to address this issue.

Users of the affected components should apply one of the following mitigations:

  • Upgrade to a currently supported Apache CXF release line (3.6.x or later) that contains the fix.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support.

Credits

  • n0mi1k (finder)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
High
ID
CVE-2026-65432
PROJECT Affected
Apache CXF
Versions Affected
<3.6.12, >=4.0.0 <4.1.8, >=4.2.0 <4.2.3
NES Versions Affected
Published date
October 1, 2026
≈ Fix date
September 29, 2026
Category
Improper Restriction of XML External Entity Reference
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Apache CXF
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.