Medium severity5.3NVD Advisory· Published Feb 20, 2023· Updated Jun 17, 2026
CVE-2016-15026
CVE-2016-15026
Description
A vulnerability was found in 3breadt dd-plist 1.17 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to xml external entity reference. An attack has to be approached locally. Upgrading to version 1.18 is able to address this issue. The patch is identified as 8c954e8d9f6f6863729e50105a8abf3f87fff74c. It is recommended to upgrade the affected component. VDB-221486 is the identifier assigned to this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.googlecode.plist:dd-plistMaven | < 1.18 | 1.18 |
Affected products
2Patches
Vulnerability mechanics
References
7- github.com/3breadt/dd-plist/commit/8c954e8d9f6f6863729e50105a8abf3f87fff74cnvdPatchWEB
- github.com/3breadt/dd-plist/pull/26nvdIssue TrackingPatchWEB
- github.com/advisories/GHSA-4jx2-hvqw-93j9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2016-15026ghsaADVISORY
- vuldb.comnvdPermissions RequiredThird Party AdvisoryWEB
- vuldb.comnvdPermissions RequiredThird Party AdvisoryWEB
- github.com/3breadt/dd-plist/releases/tag/dd-plist-1.18nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.