CVE-2019-9628: High severity Xmltooling Project Xmltooling vulnerability
Last updated 25 August 2025
Other sources
The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and propagates an unexpected exception type.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-9628?
CVE-2019-9628 has a medium severity due to improper handling of invalid XML data.
How do I fix CVE-2019-9628?
To fix CVE-2019-9628, update the XMLTooling library to version 3.0.4 or higher.
Which software versions are affected by CVE-2019-9628?
CVE-2019-9628 affects all versions of the XMLTooling library prior to 3.0.4.
Is CVE-2019-9628 relevant for Ubuntu users?
Yes, CVE-2019-9628 affects Ubuntu versions 14.04, 16.04, 18.04, and 18.10 if they are using the vulnerable XMLTooling library.
What libraries are related to CVE-2019-9628?
CVE-2019-9628 is related specifically to the XMLTooling library included in OpenSAML and Shibboleth Service Provider software.