CVE-2026-12993

A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE declarations or enable FEATURE_SECURE_PROCESSING. An attacker with artifact-write permission can upload XML documents with internal entity-expansion payloads (billion-laughs variant) that cause CPU and heap exhaustion, partially mitigated by the JAXP default 64,000 entity-expansion limit.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:build_of_apicurio_registry:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-26 00:16

Updated : 2026-08-25 15:16


NVD link : CVE-2026-12993

Mitre link : CVE-2026-12993

CVE.ORG link : CVE-2026-12993


JSON object : View

Products Affected

redhat

  • build_of_apicurio_registry
CWE
CWE-776

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')