8.7

CVE-2026-3415

XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products Allows File Reading and Denial of Service

The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validation flows. Under certain conditions, the XML parser allows the resolution of external entities when handling user-supplied XML content during validation operations. This behavior can occur when an attacker supplies crafted XML payloads to the relevant mediator flows with sufficient privileges.

Successful exploitation may allow a highly privileged actor to read files accessible within the server hosting the affected product. Additionally, it may be possible to trigger outbound requests to unintended internal or external locations, depending on the server environment and network configuration. Specially crafted XML payloads can also lead to excessive resource consumption during parsing, impacting the availability of the product.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerWSO2
Produkt WSO2 API Manager
Default Statusunaffected
Version 0
Version < 3.2.0
Status unknown
Version 3.2.0
Version < 3.2.0.472
Status affected
Version 3.2.1
Version < 3.2.1.91
Status affected
Version 4.1.0
Version < 4.1.0.254
Status affected
Version 4.2.0
Version < 4.2.0.194
Status affected
Version 4.3.0
Version < 4.3.0.105
Status affected
Version 4.4.0
Version < 4.4.0.68
Status affected
Version 4.5.0
Version < 4.5.0.53
Status affected
Version 4.6.0
Version < 4.6.0.16
Status affected
HerstellerWSO2
Produkt WSO2 Universal Gateway
Default Statusunaffected
Version 4.5.0
Version < 4.5.0.53
Status affected
Version 4.6.0
Version < 4.6.0.16
Status affected
HerstellerWSO2
Produkt WSO2 Traffic Manager
Default Statusunaffected
Version 4.5.0
Version < 4.5.0.52
Status affected
Version 4.6.0
Version < 4.6.0.16
Status affected
HerstellerWSO2
Produkt WSO2 API Control Plane
Default Statusunaffected
Version 4.5.0
Version < 4.5.0.54
Status affected
Version 4.6.0
Version < 4.6.0.17
Status affected
HerstellerWSO2
Produkt WSO2 Carbon API Gateway
Default Statusunknown
Version 6.7.206
Version < 6.7.206.594
Status affected
Version 6.7.210
Version < 6.7.210.95
Status affected
Version 9.20.74
Version < 9.20.74.398
Status affected
Version 9.28.116
Version < 9.28.116.412
Status affected
Version 9.29.120
Version < 9.29.120.228
Status affected
Version 9.30.67
Version < 9.30.67.158
Status affected
Version 9.31.86
Version < 9.31.86.147
Status affected
Version 9.32.147
Version < 9.32.147.38
Status affected
Version <= *
Version 9.33.61
Status unaffected
HerstellerWSO2
Produkt WSO2 Carbon API Management Implementation
Default Statusunknown
Version 6.7.206
Version < 6.7.206.594
Status affected
Version 6.7.210
Version < 6.7.210.95
Status affected
Version 9.20.74
Version < 9.20.74.398
Status affected
Version 9.28.116
Version < 9.28.116.412
Status affected
Version 9.29.120
Version < 9.29.120.228
Status affected
Version 9.30.67
Version < 9.30.67.158
Status affected
Version 9.31.86
Version < 9.31.86.147
Status affected
Version 9.32.147
Version < 9.32.147.38
Status affected
Version <= *
Version 9.33.61
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.269
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
ed10eef1-636d-4fbe-9993-6890dfa878f8 8.7 2.3 5.8
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:H
CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.

https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5001/