CVE-2026-12992High· 7.4▾ TwilightA flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. When the VALIDITY rule is set to FULL, an attacker with Developer-role access can upload …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 26.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. When the VALIDITY rule is set to FULL, an attacker with Developer-role access can upload a WSDL document containing attacker-controlled import locations, causing the registry to issue HTTP requests to arbitrary internal URLs (server-side request forgery).
build_of_apicurio_registry >= 3.0, <= 3.2Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-12993Medium· 6.5A flaw was found in Apicurio Registry
CVE-2026-12975High· 8.5A flaw was found in Apicurio Registry
CVE-2025-68616High· 7.5WeasyPrint helps web developers to create PDF documents
CVE-2026-42965High· 7.7A flaw was found in the OpenShift Router
CVE-2021-40438Critical· 9.0A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user
CVE-2026-32591Medium· 5.2A flaw was found in Red Hat Quay's Proxy Cache configuration feature