{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/copernik-xml-factory--0.1.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:copernik:copernik-xml-factory:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["copernik-xml-factory (\u003c 0.1.2)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","java","xml"],"_cs_type":"advisory","_cs_vendors":["Copernik"],"content_html":"\u003cp\u003eCopernik XML Factory versions through 0.1.1 contain an improper restriction of XInclude resource resolution when operating on the stock JDK provider. The library provides a guarantee that XInclude resolution remains disabled; however, this guarantee fails when an application explicitly enables XInclude via \u003ccode\u003eXmlFactories.newDocumentBuilderFactory()\u003c/code\u003e, \u003ccode\u003eXmlFactories.newSAXParserFactory()\u003c/code\u003e, or \u003ccode\u003eXmlFactories.harden()\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eIf an application parses untrusted XML and operates on the stock JDK provider (without Apache Xerces on the classpath), an attacker can inject \u003ccode\u003exi:include\u003c/code\u003e references. This flaw permits the resolution of external resources, leading to potential local file disclosure (reading sensitive system or configuration files) or Server-Side Request Forgery (SSRF) by reaching internal network endpoints via \u003ccode\u003ehttp\u003c/code\u003e hrefs. The vulnerability does not affect applications using the Xerces provider or the Android provider. The issue is tracked as CVE-2026-61586.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the unauthorized reading of local files on the server and the execution of SSRF attacks against internal network resources. This impacts Java-based applications utilizing the Copernik XML Factory library, specifically those configured to parse XML inputs from untrusted sources.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Copernik XML Factory library to version 0.1.2 or later to remediate CVE-2026-61586.\u003c/li\u003e\n\u003cli\u003eImplement a temporary workaround by adding Apache Xerces (\u003ccode\u003exercesImpl\u003c/code\u003e) to the application classpath, which forces the library to utilize the unaffected Xerces provider.\u003c/li\u003e\n\u003cli\u003eAudit applications using \u003ccode\u003eXmlFactories\u003c/code\u003e to identify and restrict untrusted XML parsing workflows.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T20:23:37Z","date_published":"2026-10-02T20:23:37Z","id":"https://feed.craftedsignal.io/briefs/2026-10-copernik-xml-xinclude/","summary":"Copernik XML Factory versions prior to 0.1.2 fail to restrict XInclude resource resolution when using the stock JDK provider, enabling local file disclosure or SSRF via malicious XML inputs.","title":"Copernik XML Factory XInclude Resource Resolution Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-10-copernik-xml-xinclude/"}],"language":"en","title":"CraftedSignal Threat Feed - Copernik-Xml-Factory (\u003c 0.1.2)","version":"https://jsonfeed.org/version/1.1"}