Skip to content

[GHSA-xw5h-cmh3-8j6j] Add fix commit reference - #10295

Open
stanleys12 wants to merge 1 commit into
github:stanleys12/advisory-improvement-10295from
stanleys12:stanleys12-GHSA-xw5h-cmh3-8j6j
Open

stanleys12 wants to merge 1 commit into
github:stanleys12/advisory-improvement-10295from
stanleys12:stanleys12-GHSA-xw5h-cmh3-8j6j

Conversation

@stanleys12

Copy link
Copy Markdown

The Apache CXF advisory for CVE-2026-49875 (https://cxf.apache.org/security-advisories.data/CVE-2026-49875.txt) says EndpointReferenceUtils and W3CMultiSchemaFactory build XML parser factories without JAXP hardening, and that 4.2.2 and 4.1.7 fix it. The fix is commit 7cfa2fb7ba0bdfe16f149257769ea5e7c6953bf9 (apache/cxf PR #3157, "More SchemaFactory hardenings"). It turns on secure-processing and disallow-doctype-decl for the SAXParserFactory in W3CMultiSchemaFactory, and blocks external DTD and schema access in EndpointReferenceUtils. It was merged on 2026-06-02 and lands in the 4.2.1→4.2.2 range, and the 4.1.x backport (bf0d2ec) is in 4.1.6→4.1.7. I'm adding the commit as a reference here.

@github-actions
github-actions Bot changed the base branch from main to stanleys12/advisory-improvement-10295 October 10, 2026 19:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant