Copernik XML Factory XInclude Resource Resolution Vulnerability
Copernik XML Factory versions prior to 0.1.2 fail to restrict XInclude resource resolution when using the stock JDK provider, enabling local file disclosure or SSRF via malicious XML inputs.
Copernik XML Factory versions through 0.1.1 contain an improper restriction of XInclude resource resolution when operating on the stock JDK provider. The library provides a guarantee that XInclude resolution remains disabled; however, this guarantee fails when an application explicitly enables XInclude via XmlFactories.newDocumentBuilderFactory(), XmlFactories.newSAXParserFactory(), or XmlFactories.harden().
If an application parses untrusted XML and operates on the stock JDK provider (without Apache Xerces on the classpath), an attacker can inject xi:include references. This flaw permits the resolution of external resources, leading to potential local file disclosure (reading sensitive system or configuration files) or Server-Side Request Forgery (SSRF) by reaching internal network endpoints via http hrefs. The vulnerability does not affect applications using the Xerces provider or the Android provider. The issue is tracked as CVE-2026-61586.
Impact
Successful exploitation allows for the unauthorized reading of local files on the server and the execution of SSRF attacks against internal network resources. This impacts Java-based applications utilizing the Copernik XML Factory library, specifically those configured to parse XML inputs from untrusted sources.
Recommendation
- Upgrade the Copernik XML Factory library to version 0.1.2 or later to remediate CVE-2026-61586.
- Implement a temporary workaround by adding Apache Xerces (
xercesImpl) to the application classpath, which forces the library to utilize the unaffected Xerces provider. - Audit applications using
XmlFactoriesto identify and restrict untrusted XML parsing workflows.
Immediate actions
Upgrade copernik-xml-factory to 0.1.2
Mitigations
Add Apache Xerces (xercesImpl) to the classpath
CVE-2026-61586