Executive brief
Proxmox storage libraries, which manage storage backends for virtual environments, contain a vulnerability in how they process XML data. An attacker could exploit this to access sensitive files on the host system or perform internal network scanning. This could lead to the exposure of private configuration data or unauthorized access to internal services.
Technical details
An XML External Entity (XXE) vulnerability exists in libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7. The vulnerability likely stems from insecure XML parsing configurations that allow the resolution of external entities. An attacker who can influence XML input processed by these storage libraries could potentially read arbitrary files from the host filesystem or conduct Server-Side Request Forgery (SSRF) attacks. While the advisory lists the severity as 'info', XXE vulnerabilities typically carry a higher risk profile depending on the privileges of the service running the Perl library.
Affected products
- Proxmox libpvestorage-perl 9.1.1
- Proxmox libpve-storage-perl 8.3.7
Timeline
- 2026-07-17: disclosed: CVE published to NVD