Skip to content

[GHSA-w8wc-5pf9-6ph5] Improper Restriction of XML External Entity Reference in the XSLT support... - #10093

Draft
oscerd wants to merge 1 commit into
github:oscerd/advisory-improvement-10093from
oscerd:oscerd-GHSA-w8wc-5pf9-6ph5
Draft

oscerd wants to merge 1 commit into
github:oscerd/advisory-improvement-10093from
oscerd:oscerd-GHSA-w8wc-5pf9-6ph5

Conversation

@oscerd

@oscerd oscerd commented Oct 2, 2026

Copy link
Copy Markdown

[GHSA-w8wc-5pf9-6ph5] Improper Restriction of XML External Entity Reference in the XSLT support...

Updates

  • Affected products
  • Source code location

Comments
Affected packages, version ranges and source code location are taken from the official Apache Camel security advisory: https://camel.apache.org/security/CVE-2026-88789.html (mirrored at http://www.openwall.com/lists/oss-security/2026/10/01/1), which states "This issue affects Apache Camel Quarkus: from 3.2.0 before 3.33.3, from 3.34.0 before 3.40.0".

The flaw is in the camel-quarkus-support-xalan extension, and the advisory names the four extensions that bring it onto the classpath: camel-quarkus-xslt, camel-quarkus-xslt-saxon, camel-quarkus-tika and camel-quarkus-xmlsecurity. All five are listed here, since a dependency on any of them pulls in the vulnerable factory (for all but camel-quarkus-xslt the exposure is limited to the JAXP default factory). Every artifact is published on Maven Central under org.apache.camel.quarkus for both streams.

Note on the second stream: 3.34.0 was never released (3.33.3 is followed by 3.35.0 on Maven Central), so the first published affected version on that line is 3.35.0. The introduced value is kept as the advisory states it.

Claude Code on behalf of oscerd

🤖 Generated with Claude Code

…erence in the XSLT support...

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: Andrea Cosentino <ancosen@gmail.com>
@github-actions
github-actions Bot changed the base branch from main to oscerd/advisory-improvement-10093 October 2, 2026 07:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant