High severity7.5NVD Advisory· Published Aug 6, 2026· Updated Aug 7, 2026
CVE-2026-65432
CVE-2026-65432
Description
Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <xsd:import> referenced from that top-level WSDL is handed off to WSDL4J, which does not disable DOCTYPE declarations or external entities. As a result, the protections applied to the top-level document do not extend to imported documents, leaving imported WSDL/XSD content vulnerable to XML External Entity (XXE) attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- lists.apache.org/thread/5qs207krzg51jl3zs3cvnl5lt9njp8c3nvdMailing ListVendor Advisory
- www.openwall.com/lists/oss-security/2026/08/06/17nvd
News mentions
0No linked articles in our index yet.