This is an automated email from the ASF dual-hosted git repository.

jamesnetherton pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel-website.git


The following commit(s) were added to refs/heads/main by this push:
     new 0343cba5 Add CVE-2026-88789
0343cba5 is described below

commit 0343cba5dc8c523c304f71a3614c0415882e480e
Author: James Netherton <[email protected]>
AuthorDate: Wed Sep 30 14:11:43 2026 +0100

    Add CVE-2026-88789
---
 content/security/CVE-2026-88789.md      | 23 ++++++++++++++++++++
 content/security/CVE-2026-88789.txt.asc | 38 +++++++++++++++++++++++++++++++++
 2 files changed, 61 insertions(+)

diff --git a/content/security/CVE-2026-88789.md 
b/content/security/CVE-2026-88789.md
new file mode 100644
index 00000000..61d110a6
--- /dev/null
+++ b/content/security/CVE-2026-88789.md
@@ -0,0 +1,23 @@
+---
+title: "Apache Camel Security Advisory - CVE-2026-88789"
+url: /security/CVE-2026-88789.html
+date: 2026-09-30T09:39:19+01:00
+draft: false
+type: security-advisory
+cve: CVE-2026-88789
+severity: HIGH
+summary: "Camel Quarkus: Forced Xalan TransformerFactory drops upstream 
external-DTD/stylesheet hardening"
+description: "Improper Restriction of XML External Entity Reference in the 
XSLT support extension (camel-quarkus-support-xalan) in Apache Camel Quarkus 
allows an attacker who supplies the XML document being transformed to read 
local files or issue requests to internal network locations via an external 
entity declaration in that document. This issue affects Apache Camel Quarkus: 
from 3.2.0 before 3.33.3, from 3.34.0 before 3.40.0. The extension supplies its 
own Xalan-backed TransformerFac [...]
+mitigation: "Users are recommended to upgrade to version 3.40.0, which fixes 
the issue. Users on the 3.33.x LTS release stream are suggested to upgrade to 
3.33.3. For deployments that cannot upgrade immediately, do not pass a 
javax.xml.transform.Source built from untrusted input into an xslt endpoint: 
leave the message body as String, byte[] or InputStream so that Apache Camel 
converts it to a SAXSource with external entities disabled before the 
transformation. Note that converting an ex [...]
+credit: "This issue was discovered by internal analysis"
+affected: "This issue affects Apache Camel Quarkus: from 3.2.0 before 3.33.3, 
from 3.34.0 before 3.40.0"
+fixed: 3.33.3 and 3.40.0
+---
+
+The GitHub issue https://github.com/apache/camel-quarkus/issues/9115 refers to 
the commits that resolved the issue, and has more details.
+
+The fix was merged on main in 
https://github.com/apache/camel-quarkus/commit/9a570b64977b0e24f85d67c2b2220aeac9fa5274
 and 
https://github.com/apache/camel-quarkus/commit/9dd11779580cd88e4ab01b23717cd0167f26155c,
 and backported to the 3.33.x branch in 
https://github.com/apache/camel-quarkus/commit/ad9c52365dc85eac029e8bfe3899aee07e48a525
 and 
https://github.com/apache/camel-quarkus/commit/3d8867697c105c0d648fdcfe07f8dd7159cb3d47.
+
+XalanTransformerFactory now applies the restrictions itself rather than 
relying on attributes Xalan cannot honour. Documents being transformed are 
parsed with an XMLReader that resolves neither external general nor external 
parameter entities and does not load external DTDs, which is the configuration 
Apache Camel's XmlConverter.createSAXParserFactory uses for the bodies 
camel-xslt converts to a SAXSource itself; a SAXSource carrying a 
caller-configured XMLReader is used as it is, and DO [...]
+
+The issue is classified as CWE-611 (Improper Restriction of XML External 
Entity Reference).
diff --git a/content/security/CVE-2026-88789.txt.asc 
b/content/security/CVE-2026-88789.txt.asc
new file mode 100644
index 00000000..9f82c5e6
--- /dev/null
+++ b/content/security/CVE-2026-88789.txt.asc
@@ -0,0 +1,38 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+- ---
+title: "Apache Camel Security Advisory - CVE-2026-88789"
+url: /security/CVE-2026-88789.html
+date: 2026-09-30T09:39:19+01:00
+draft: false
+type: security-advisory
+cve: CVE-2026-88789
+severity: HIGH
+summary: "Camel Quarkus: Forced Xalan TransformerFactory drops upstream 
external-DTD/stylesheet hardening"
+description: "Improper Restriction of XML External Entity Reference in the 
XSLT support extension (camel-quarkus-support-xalan) in Apache Camel Quarkus 
allows an attacker who supplies the XML document being transformed to read 
local files or issue requests to internal network locations via an external 
entity declaration in that document. This issue affects Apache Camel Quarkus: 
from 3.2.0 before 3.33.3, from 3.34.0 before 3.40.0. The extension supplies its 
own Xalan-backed TransformerFac [...]
+mitigation: "Users are recommended to upgrade to version 3.40.0, which fixes 
the issue. Users on the 3.33.x LTS release stream are suggested to upgrade to 
3.33.3. For deployments that cannot upgrade immediately, do not pass a 
javax.xml.transform.Source built from untrusted input into an xslt endpoint: 
leave the message body as String, byte[] or InputStream so that Apache Camel 
converts it to a SAXSource with external entities disabled before the 
transformation. Note that converting an ex [...]
+credit: "This issue was discovered by internal analysis"
+affected: "This issue affects Apache Camel Quarkus: from 3.2.0 before 3.33.3, 
from 3.34.0 before 3.40.0"
+fixed: 3.33.3 and 3.40.0
+- ---
+
+The GitHub issue https://github.com/apache/camel-quarkus/issues/9115 refers to 
the commits that resolved the issue, and has more details.
+
+The fix was merged on main in 
https://github.com/apache/camel-quarkus/commit/9a570b64977b0e24f85d67c2b2220aeac9fa5274
 and 
https://github.com/apache/camel-quarkus/commit/9dd11779580cd88e4ab01b23717cd0167f26155c,
 and backported to the 3.33.x branch in 
https://github.com/apache/camel-quarkus/commit/ad9c52365dc85eac029e8bfe3899aee07e48a525
 and 
https://github.com/apache/camel-quarkus/commit/3d8867697c105c0d648fdcfe07f8dd7159cb3d47.
+
+XalanTransformerFactory now applies the restrictions itself rather than 
relying on attributes Xalan cannot honour. Documents being transformed are 
parsed with an XMLReader that resolves neither external general nor external 
parameter entities and does not load external DTDs, which is the configuration 
Apache Camel's XmlConverter.createSAXParserFactory uses for the bodies 
camel-xslt converts to a SAXSource itself; a SAXSource carrying a 
caller-configured XMLReader is used as it is, and DO [...]
+
+The issue is classified as CWE-611 (Improper Restriction of XML External 
Entity Reference).
+-----BEGIN PGP SIGNATURE-----
+
+iQFPBAEBCgA5FiEE6yNzJrQjDCjWD461r1rK8KHocpIFAmq82g8bFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEK9ayvCh6HKSrFIH/Rc/oWq1UH+vwnDJ01pn
+wm8cIijrYKPj1Quiwn6oruvA+y1VzlB0AX3n2CrLAqzf/+XQDqFtA+G75NEX1Azl
+b/BCEgEFUa3kuXum3NSiaErpEM3BJx2KrJCR3QDfLWpSwSUtySqXAyUHEqwj3ynf
+arRIZYCW4pZkMX5klhBHoB9SxICqh1ptQ12BoTy3SoeS4KSkBe9zT2WL1zRmMvjk
+1puELLjFOq5HYvTKbZFd1UGYldoYswMUdjcCxcWjzWzPEglBGBA7N7kjmntiYscN
+TNyvtr66URqnO0i0hHQXMVj+fdCkHQ2lSol0B97a0ANqtf1Ph54juwS4mRDPdcIZ
+FEQ=
+=5cIb
+-----END PGP SIGNATURE-----

Reply via email to