This is an automated email from the ASF dual-hosted git repository.
jamesnetherton pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel-website.git
The following commit(s) were added to refs/heads/main by this push:
new 0343cba5 Add CVE-2026-88789
0343cba5 is described below
commit 0343cba5dc8c523c304f71a3614c0415882e480e
Author: James Netherton <[email protected]>
AuthorDate: Wed Sep 30 14:11:43 2026 +0100
Add CVE-2026-88789
---
content/security/CVE-2026-88789.md | 23 ++++++++++++++++++++
content/security/CVE-2026-88789.txt.asc | 38 +++++++++++++++++++++++++++++++++
2 files changed, 61 insertions(+)
diff --git a/content/security/CVE-2026-88789.md
b/content/security/CVE-2026-88789.md
new file mode 100644
index 00000000..61d110a6
--- /dev/null
+++ b/content/security/CVE-2026-88789.md
@@ -0,0 +1,23 @@
+---
+title: "Apache Camel Security Advisory - CVE-2026-88789"
+url: /security/CVE-2026-88789.html
+date: 2026-09-30T09:39:19+01:00
+draft: false
+type: security-advisory
+cve: CVE-2026-88789
+severity: HIGH
+summary: "Camel Quarkus: Forced Xalan TransformerFactory drops upstream
external-DTD/stylesheet hardening"
+description: "Improper Restriction of XML External Entity Reference in the
XSLT support extension (camel-quarkus-support-xalan) in Apache Camel Quarkus
allows an attacker who supplies the XML document being transformed to read
local files or issue requests to internal network locations via an external
entity declaration in that document. This issue affects Apache Camel Quarkus:
from 3.2.0 before 3.33.3, from 3.34.0 before 3.40.0. The extension supplies its
own Xalan-backed TransformerFac [...]
+mitigation: "Users are recommended to upgrade to version 3.40.0, which fixes
the issue. Users on the 3.33.x LTS release stream are suggested to upgrade to
3.33.3. For deployments that cannot upgrade immediately, do not pass a
javax.xml.transform.Source built from untrusted input into an xslt endpoint:
leave the message body as String, byte[] or InputStream so that Apache Camel
converts it to a SAXSource with external entities disabled before the
transformation. Note that converting an ex [...]
+credit: "This issue was discovered by internal analysis"
+affected: "This issue affects Apache Camel Quarkus: from 3.2.0 before 3.33.3,
from 3.34.0 before 3.40.0"
+fixed: 3.33.3 and 3.40.0
+---
+
+The GitHub issue https://github.com/apache/camel-quarkus/issues/9115 refers to
the commits that resolved the issue, and has more details.
+
+The fix was merged on main in
https://github.com/apache/camel-quarkus/commit/9a570b64977b0e24f85d67c2b2220aeac9fa5274
and
https://github.com/apache/camel-quarkus/commit/9dd11779580cd88e4ab01b23717cd0167f26155c,
and backported to the 3.33.x branch in
https://github.com/apache/camel-quarkus/commit/ad9c52365dc85eac029e8bfe3899aee07e48a525
and
https://github.com/apache/camel-quarkus/commit/3d8867697c105c0d648fdcfe07f8dd7159cb3d47.
+
+XalanTransformerFactory now applies the restrictions itself rather than
relying on attributes Xalan cannot honour. Documents being transformed are
parsed with an XMLReader that resolves neither external general nor external
parameter entities and does not load external DTDs, which is the configuration
Apache Camel's XmlConverter.createSAXParserFactory uses for the bodies
camel-xslt converts to a SAXSource itself; a SAXSource carrying a
caller-configured XMLReader is used as it is, and DO [...]
+
+The issue is classified as CWE-611 (Improper Restriction of XML External
Entity Reference).
diff --git a/content/security/CVE-2026-88789.txt.asc
b/content/security/CVE-2026-88789.txt.asc
new file mode 100644
index 00000000..9f82c5e6
--- /dev/null
+++ b/content/security/CVE-2026-88789.txt.asc
@@ -0,0 +1,38 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA512
+
+- ---
+title: "Apache Camel Security Advisory - CVE-2026-88789"
+url: /security/CVE-2026-88789.html
+date: 2026-09-30T09:39:19+01:00
+draft: false
+type: security-advisory
+cve: CVE-2026-88789
+severity: HIGH
+summary: "Camel Quarkus: Forced Xalan TransformerFactory drops upstream
external-DTD/stylesheet hardening"
+description: "Improper Restriction of XML External Entity Reference in the
XSLT support extension (camel-quarkus-support-xalan) in Apache Camel Quarkus
allows an attacker who supplies the XML document being transformed to read
local files or issue requests to internal network locations via an external
entity declaration in that document. This issue affects Apache Camel Quarkus:
from 3.2.0 before 3.33.3, from 3.34.0 before 3.40.0. The extension supplies its
own Xalan-backed TransformerFac [...]
+mitigation: "Users are recommended to upgrade to version 3.40.0, which fixes
the issue. Users on the 3.33.x LTS release stream are suggested to upgrade to
3.33.3. For deployments that cannot upgrade immediately, do not pass a
javax.xml.transform.Source built from untrusted input into an xslt endpoint:
leave the message body as String, byte[] or InputStream so that Apache Camel
converts it to a SAXSource with external entities disabled before the
transformation. Note that converting an ex [...]
+credit: "This issue was discovered by internal analysis"
+affected: "This issue affects Apache Camel Quarkus: from 3.2.0 before 3.33.3,
from 3.34.0 before 3.40.0"
+fixed: 3.33.3 and 3.40.0
+- ---
+
+The GitHub issue https://github.com/apache/camel-quarkus/issues/9115 refers to
the commits that resolved the issue, and has more details.
+
+The fix was merged on main in
https://github.com/apache/camel-quarkus/commit/9a570b64977b0e24f85d67c2b2220aeac9fa5274
and
https://github.com/apache/camel-quarkus/commit/9dd11779580cd88e4ab01b23717cd0167f26155c,
and backported to the 3.33.x branch in
https://github.com/apache/camel-quarkus/commit/ad9c52365dc85eac029e8bfe3899aee07e48a525
and
https://github.com/apache/camel-quarkus/commit/3d8867697c105c0d648fdcfe07f8dd7159cb3d47.
+
+XalanTransformerFactory now applies the restrictions itself rather than
relying on attributes Xalan cannot honour. Documents being transformed are
parsed with an XMLReader that resolves neither external general nor external
parameter entities and does not load external DTDs, which is the configuration
Apache Camel's XmlConverter.createSAXParserFactory uses for the bodies
camel-xslt converts to a SAXSource itself; a SAXSource carrying a
caller-configured XMLReader is used as it is, and DO [...]
+
+The issue is classified as CWE-611 (Improper Restriction of XML External
Entity Reference).
+-----BEGIN PGP SIGNATURE-----
+
+iQFPBAEBCgA5FiEE6yNzJrQjDCjWD461r1rK8KHocpIFAmq82g8bFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEK9ayvCh6HKSrFIH/Rc/oWq1UH+vwnDJ01pn
+wm8cIijrYKPj1Quiwn6oruvA+y1VzlB0AX3n2CrLAqzf/+XQDqFtA+G75NEX1Azl
+b/BCEgEFUa3kuXum3NSiaErpEM3BJx2KrJCR3QDfLWpSwSUtySqXAyUHEqwj3ynf
+arRIZYCW4pZkMX5klhBHoB9SxICqh1ptQ12BoTy3SoeS4KSkBe9zT2WL1zRmMvjk
+1puELLjFOq5HYvTKbZFd1UGYldoYswMUdjcCxcWjzWzPEglBGBA7N7kjmntiYscN
+TNyvtr66URqnO0i0hHQXMVj+fdCkHQ2lSol0B97a0ANqtf1Ph54juwS4mRDPdcIZ
+FEQ=
+=5cIb
+-----END PGP SIGNATURE-----