VYPR

XML Factory

by Copernik

CVEs (1)

  • CVE-2026-61586higOct 2, 2026
    risk 0.38cvss —epss —

    Copernik XML Factory through `0.1.1`, when running on its stock JDK provider, does not block XInclude resource resolution after an application enables XInclude on a factory returned by `XmlFactories.newDocumentBuilderFactory()` or `XmlFactories.newSAXParserFactory()`, or on an…