CVE-2026-78224

The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-11 15:17

Updated : 2026-09-11 15:17


NVD link : CVE-2026-78224

Mitre link : CVE-2026-78224

CVE.ORG link : CVE-2026-78224


JSON object : View

Products Affected

No product.

CWE
CWE-611

Improper Restriction of XML External Entity Reference