Improper XML External Entity Handling in Apache Camel Quarkus
CVE-2026-88789
8.6HIGH
What is CVE-2026-88789?
A vulnerability in the Apache Camel Quarkus XSLT support extension allows attackers to read local files or issue requests to internal network locations through XML external entity declarations. This weakness exists due to the extension's use of an outdated TransformerFactory that does not adhere to access controls for external DTD and stylesheets. As a result, applications leveraging the affected versions without appropriate safeguards are at risk. Users are highly encouraged to upgrade to safe versions (3.33.3 or 3.40.0) to mitigate potential exposure.
Affected Version(s)
Apache Camel Quarkus 3.2.0 < 3.33.3
Apache Camel Quarkus 3.34.0 < 3.40.0
Apache Camel Quarkus 3.33.3