XML External Entity Injection via Publisher in WSO2 API Manager Allows Reading Arbitrary Files
Published Apr 16, 2026
7.5
HIGHCVSS 3.1
EPSS 0.27%
Description
The component accepts XML input through the publisher without disabling external entity resolution. This allows malicious actors to submit a crafted XML payload that exploits the unescaped external entity references.
By leveraging this vulnerability, a malicious actor can read confidential files from the product's file system or access limited HTTP resources reachable via HTTP GET requests to the vulnerable product.
Affected products
-
- Version 3.2.0StatusaffectedConstraints<3.2.0.397
- Version 3.2.1StatusaffectedConstraints<3.2.1.27
- Version 4.0.0StatusaffectedConstraints<4.0.0.310
- Version 4.0.0StatusaffectedConstraints<4.0.0.319
- Version 4.1.0StatusaffectedConstraints<4.1.0.171
- Version 4.2.0StatusaffectedConstraints<4.2.0.127
- Version 4.3.0StatusaffectedConstraints<4.3.0.39
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| WSO2 | WSO2 API Manager | unaffected |
|
- ≥ 3.2.0 · < 3.2.0.397
- ≥ 3.2.1 · < 3.2.1.27
- ≥ 4.0.0 · ≤ 4.0.0.310
- ≥ 4.1.0 · < 4.1.0.171
- ≥ 4.2.0 · < 4.2.0.127
- ≥ 4.3.0 · < 4.3.0.39
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3581/#solution
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-55549 Advisory
- https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3581/ vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-55549 | Advisory | |
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3581/ | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.