HIGH GitHub

CVE-2026-61586

Copernik XML Factory (stock JDK provider) has Improper restriction of XInclude resource resolution

Copernik XML Factory through `0.1.1`, when running on its stock JDK provider, does not block XInclude resource resolution after an application enables XInclude on a factory returned by `XmlFactories.newDocumentBuilderFactory()` or `XmlFactories.newSAXParserFactory()`, or on an `XMLReader` passed through `XmlFactories.harden()`. The library's documented guarantee that XInclude resolution stays disabled therefore does not hold on that provider. An application that parses untrusted XML in this con

Affected Products

References

Published: 2026-10-02 · Source: GitHub · Feed updated: 2026-10-02
This high severity vulnerability was published on 2026-10-02 via GitHub. Affected: maven/eu.copernik:copernik-xml-factory < 0.1.2.
vulnfeed aggregates 10027 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.