Improper XML Handling in Apache SIS Leading to File Exposure
CVE-2025-68280
What is CVE-2025-68280?
Apache SIS contains a vulnerability due to improper handling of XML External Entity (XXE) references, allowing maliciously crafted XML files to expose sensitive local files on the server hosting the application. This issue affects various SIS services, including GeoTIFF file reading, ISO 19115 metadata parsing, and GML-defined Coordinate Reference Systems, as well as GPS Exchange Format (GPX) file parsing. Users are advised to upgrade to version 1.6 to resolve this vulnerability. In the interim, implementing restrictions on the Java XML parsing options can mitigate risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache SIS 0.4 <= 1.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved