Executive brief
An XSLT processing component fails to properly configure its XML transformation engine with security protections, allowing attackers to inject malicious XML entity definitions. This can lead to unauthorized file disclosure from the affected system and cause resource exhaustion attacks that disrupt service availability.
Technical details
This vulnerability is an XML External Entity (XXE) injection flaw in an XSLT Transformer Step that instantiates a TransformerFactory without disabling external entity processing and other XML attack surface hardening. The root cause is the lack of security-focused factory attribute configuration (such as disabling DOCTYPE declarations, entity expansion, and external schema access). An attacker who can supply or influence XSLT input can craft malicious XML payloads to read arbitrary files from the system (data exfiltration) or trigger billion-laughs/quadratic blowup denial-of-service attacks. The attack vector depends on whether XSLT input is network-accessible or requires local/authenticated access; no fix availability is mentioned in the advisory text.
Affected products
- <UNKNOWN>
Timeline
- 2026-09-11: disclosed