Intel

AIKIDO-2026-400602

spring-xml is vulnerable to XML External Entity (XXE) Attack

XML External Entity (XXE) AttackCVE-2026-40998 Published Today

80

High Risk

This Affects:

javaspring-xml
0.0.1 - 3.1.8
Fixed in 3.1.9
4.0.0 - 4.0.18
Fixed in 4.0.19
4.1.0 - 4.1.3
Fixed in 4.1.3.1
5.0.0 - 5.0.1
Fixed in 5.0.1.1
Are you affected? Scan for Free

TL;DR

Spring Web Services contains an XML External Entity (XXE) vulnerability in Jaxp13XPathTemplate when evaluating XPath expressions against StreamSource or SAXSource inputs. Due to the use of an XML parser configuration that does not apply Spring's hardened settings, applications processing untrusted XML may allow attackers to resolve external entities. Successful exploitation can result in sensitive file disclosure, server-side request forgery, or other impacts depending on the environment and parser configuration.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spring-xml is vulnerable to XML External Entity (XXE) Attack in versions 0.0.1 - 3.1.8, 4.0.0 - 4.0.18, 4.1.0 - 4.1.3 and 5.0.0 - 5.0.1.

How to fix this

Upgrade the org.springframework.ws:spring-xml library to a patch version.