HIGH GitHub
CVE-2026-61586
Copernik XML Factory (stock JDK provider) has Improper restriction of XInclude resource resolution
Copernik XML Factory through `0.1.1`, when running on its stock JDK provider, does not block XInclude resource resolution after an application enables XInclude on a factory returned by `XmlFactories.newDocumentBuilderFactory()` or `XmlFactories.newSAXParserFactory()`, or on an `XMLReader` passed through `XmlFactories.harden()`. The library's documented guarantee that XInclude resolution stays disabled therefore does not hold on that provider.
An application that parses untrusted XML in this con
Affected Products
- maven/eu.copernik:copernik-xml-factory < 0.1.2
References
- https://github.com/advisories/GHSA-xm28-xvqc-gxxg
- https://github.com/copernik-eu/copernik-xml-factory/security/advisories/GHSA-xm28-xvqc-gxx
- https://github.com/copernik-eu/copernik-xml-factory/commit/2fa042c44931b0a4ddd585d62b97a8a
- https://github.com/copernik-eu/copernik-xml-factory/commit/e5febc6039ed4b0088245acb80ed7d6
This high severity vulnerability was published on 2026-10-02 via GitHub. Affected: maven/eu.copernik:copernik-xml-factory < 0.1.2.
vulnfeed aggregates 10027 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.