CVE-2026-88789
Camel Quarkus Xalan TransformerFactory drops XXE hardening
Apache Camel Quarkus camel-quarkus-support-xalan registers a Xalan-backed TransformerFactory that ignores JAXP ACCESS_EXTERNAL_DTD and ACCESS_EXTERNAL_STYLESHEET, allowing XXE that can read local files or reach internal network locations. Apache scores CVSS 3.1 8.6. Fixed in 3.33.3 and 3.40.0. A public reproducer exists. Not in CISA KEV.
- CVSS
- 8.6
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- Class
- Other
- Status
- PoC Available
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- Apache
- Products
- Apache Camel Quarkus, camel-quarkus-support-xalan
- Affected
- Apache Camel Quarkus 3.2.0 before 3.33.3, and 3.34.0 before 3.40.0, when any of camel-quarkus-xslt, camel-quarkus-xslt-saxon, camel-quarkus-tika, or camel-quarkus-xmlsecurity brings camel-quarkus-support-xalan onto the classpath.
- Fixed
- 3.33.3 (3.33.x LTS) and 3.40.0.
- CWE
- CWE-611
- Published
- 1 Oct 2026
- Updated
- 5 Oct 2026
The status above is the claim. Links do not upgrade it.
CVE-2026-88789 is an XML external entity flaw in the Apache Camel Quarkus XSLT support extension camel-quarkus-support-xalan. Apache's advisory says the extension supplies its own Xalan-backed TransformerFactory to the xslt component and registers it as the JAXP default. Xalan-J 2.7.x predates JAXP 1.5 and does not honour ACCESS_EXTERNAL_DTD or ACCESS_EXTERNAL_STYLESHEET, so the external-access restrictions Apache Camel applies to that factory were not in effect. An attacker who supplies the XML document being transformed can declare an external entity and read local files or issue requests to internal network locations. Apache classifies this as CWE-611 and rates severity High.
Apache's CVSS 3.1 score is 8.6 with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N, published through security@apache.org and recorded by NVD as a Secondary metric. NVD vulnStatus is Deferred. CISA's SSVC assessment for this CVE sets exploitation to none. The CVE is not in the CISA KEV catalog.
Affected versions are Camel Quarkus 3.2.0 before 3.33.3 and 3.34.0 before 3.40.0. Applications are in scope when they use camel-quarkus-xslt, camel-quarkus-xslt-saxon, camel-quarkus-tika, or camel-quarkus-xmlsecurity, each of which pulls camel-quarkus-support-xalan onto the classpath. On the xslt path, only message bodies that already arrive as a javax.xml.transform.Source are exposed; String, byte[], and InputStream bodies that Camel converts to a SAXSource with external entities disabled are not. For the non-xslt extensions, exposure is limited to the JAXP default factory. Fixed versions are 3.33.3 and 3.40.0.
A public repository at github.com/oscerd/CVE-2026-88789 describes itself as a runnable reproducer for this CVE against Camel Quarkus. The owner account oscerd is Andrea Cosentino, whose public profile identifies him as an Apache Camel / Apache Member. ThreatWire did not reproduce the project. This record does not reprint requests, entity payloads, or commands. Exploitation in the wild is not confirmed by Apache or CISA.