<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Copernik-Xml-Factory (&lt; 0.1.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/copernik-xml-factory--0.1.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 20:23:37 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/copernik-xml-factory--0.1.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Copernik XML Factory XInclude Resource Resolution Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-10-copernik-xml-xinclude/</link><pubDate>Fri, 02 Oct 2026 20:23:37 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-copernik-xml-xinclude/</guid><description>Copernik XML Factory versions prior to 0.1.2 fail to restrict XInclude resource resolution when using the stock JDK provider, enabling local file disclosure or SSRF via malicious XML inputs.</description><content:encoded><![CDATA[<p>Copernik XML Factory versions through 0.1.1 contain an improper restriction of XInclude resource resolution when operating on the stock JDK provider. The library provides a guarantee that XInclude resolution remains disabled; however, this guarantee fails when an application explicitly enables XInclude via <code>XmlFactories.newDocumentBuilderFactory()</code>, <code>XmlFactories.newSAXParserFactory()</code>, or <code>XmlFactories.harden()</code>.</p>
<p>If an application parses untrusted XML and operates on the stock JDK provider (without Apache Xerces on the classpath), an attacker can inject <code>xi:include</code> references. This flaw permits the resolution of external resources, leading to potential local file disclosure (reading sensitive system or configuration files) or Server-Side Request Forgery (SSRF) by reaching internal network endpoints via <code>http</code> hrefs. The vulnerability does not affect applications using the Xerces provider or the Android provider. The issue is tracked as CVE-2026-61586.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the unauthorized reading of local files on the server and the execution of SSRF attacks against internal network resources. This impacts Java-based applications utilizing the Copernik XML Factory library, specifically those configured to parse XML inputs from untrusted sources.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the Copernik XML Factory library to version 0.1.2 or later to remediate CVE-2026-61586.</li>
<li>Implement a temporary workaround by adding Apache Xerces (<code>xercesImpl</code>) to the application classpath, which forces the library to utilize the unaffected Xerces provider.</li>
<li>Audit applications using <code>XmlFactories</code> to identify and restrict untrusted XML parsing workflows.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>java</category><category>xml</category></item></channel></rss>