XML External Entity Injection in NanoXML by Thales
CVE-2026-19614
5.3MEDIUM
What is CVE-2026-19614?
The XML parsing mechanism in NanoXML version 2.2.3 is susceptible to XML External Entity (XXE) injection attacks. By default, the support for XML external entities is enabled, which could allow attackers to exploit this vulnerability for various attacks. This may lead to unauthorized access to sensitive data and enable other security risks, showcasing the importance of applying security patches and configurations to mitigate potential threats.
Affected Version(s)
NanoXML 2.2.3
