Improper XML External Entity Handling in Apache Camel Quarkus
CVE-2026-88789

8.6HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
1 October 2026

What is CVE-2026-88789?

A vulnerability in the Apache Camel Quarkus XSLT support extension allows attackers to read local files or issue requests to internal network locations through XML external entity declarations. This weakness exists due to the extension's use of an outdated TransformerFactory that does not adhere to access controls for external DTD and stylesheets. As a result, applications leveraging the affected versions without appropriate safeguards are at risk. Users are highly encouraged to upgrade to safe versions (3.33.3 or 3.40.0) to mitigate potential exposure.

Affected Version(s)

Apache Camel Quarkus 3.2.0 < 3.33.3

Apache Camel Quarkus 3.34.0 < 3.40.0

Apache Camel Quarkus 3.33.3

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.