Index
Search
Search the public record. Drafts and scheduled notes are not included.
High
news
Camel Quarkus XXE is CVE-2026-88789
Apache disclosed CVE-2026-88789 in Camel Quarkus: the Xalan-backed XSLT support factory drops JAXP external-access hardening, enabling XXE that can read local files or reach internal hosts. CVSS 3.1 8.6 from Apache. Fixed in 3.33.3 and 3.40.0. A public reproducer exists. Not in CISA KEV.
Published 2h ago
HighPoC Available
CVE-2026-88789
Camel Quarkus Xalan TransformerFactory drops XXE hardening
Other
Published 4d ago