{"id":"CVE-2026-19614","title":"The API is prone to XML external entity (XXE) injection","summary":"The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled.\nThis issue affects NanoXML: 2.2.3.","severity":"medium","cvss":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N","cwe":["CWE-611"],"vendor":"CyberELF","product":"NanoXML","affected":["NanoXML 2.2.3"],"published":"2026-09-08","updated":"2026-09-09","sourceUpdated":"2026-09-09T15:46:07.450","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19614","references":[{"url":"https://www.thalesgroup.com/en/search/cybersecurity/cybersecurity-services/cve-2026-19614","label":"64c5ae8f-7972-4697-86a0-7ada793ac795"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-08T12:19:42.810404Z"},"cvssSource":"cna","ingestedAt":"2026-09-08T15:33:26.983Z","epss":0.00232,"epssPercentile":0.14286,"slug":"CVE-2026-19614","body":"## Overview\n\nThe API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled.\nThis issue affects NanoXML: 2.2.3.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}