VYPR
High severity7.5NVD Advisory· Published Feb 27, 2026· Updated Jun 17, 2026

CVE-2026-2252

CVE-2026-2252

Description

An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML input containing malicious external entity references.

This issue affects Xerox FreeFlow Core versions up to and including 8.0.7.

Please consider upgrading to FreeFlow Core version 8.1.0 via the software available on -  https://www.support.xerox.com/en-us/product/core/downloads

Affected products

3
  • Xerox/Freeflow Corellm-fuzzy3 versions
    <=8.0.7+ 2 more
    • (no CPE)range: <=8.0.7
    • (no CPE)range: 0
    • cpe:2.3:a:xerox:freeflow_core:*:*:*:*:*:*:*:*range: <8.1.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.