{"id":"CVE-2026-49875","title":"Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) \nexternal entity resolution. Users are recommended to upgr…","summary":"Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) \nexternal entity resolution. Users are recommended to upgr…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-611"],"vendor":"apache","product":"cxf","affected":["cxf < 4.1.7","cxf >= 4.2.0, < 4.2.2"],"patched":["cxf 4.2.2"],"published":"2026-06-12","updated":"2026-07-28","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-49875","references":[{"url":"https://lists.apache.org/thread/3kb9w5bg90xcp06fccoz9k3gpsvyy79o","label":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/06/11/2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2026:36839","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:37390","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-49875","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2488309","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49875.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-49875"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49875"}],"tags":["nvd","csaf","vex","red-hat","score-dispute"],"epss":0.00525,"epssPercentile":0.43299,"ingestedAt":"2026-07-28T17:37:22.159Z","scores":{"nvd":9.8,"vendor":7.5},"slug":"CVE-2026-49875","body":"## Overview\n\nApache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) \nexternal entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.\n\n## Affected\n\n- `cxf < 4.1.7`\n- `cxf >= 4.2.0, < 4.2.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `cxf 4.2.2`\n\n## Vendor advisories\n\n- **RHSA-2026:37390** · Red Hat · fixed in: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16 · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:37390)\n- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Web Server 5, Red Hat Single Sign-On 7 · no fix planned: Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Web Server 5, Red Hat Single Sign-On 7, … · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49875.json)","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}