CVE-2024-2374: XML External Entity Injection in Multiple WSO2 Products Allows Arbitrary file read and Denial of Service

Published Apr 16, 2026
·
Updated

The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entities. This omission allows malicious actors to craft XML payloads that exploit the parser's behavior, leading to the inclusion of external resources.

By leveraging this vulnerability, an attacker can read confidential files from the file system and access limited HTTP resources reachable by the product. Additionally, the vulnerability can be exploited to perform denial of service attacks by exhausting server resources through recursive entity expansion or fetching large external resources.

Affected Software

13 affected components
WSO2 API Manager>=3.1.0<3.1.0.278
WSO2 API Manager>=3.2.0<3.2.0.368
WSO2 API Manager>=4.0.0<4.0.0.280
WSO2 API Manager>=4.1.0<4.1.0.206
WSO2 API Manager>=4.2.0<4.2.0.144
WSO2 API Manager>=4.3.0<4.3.0.57
WSO2 Identity Server>=5.10.0<5.10.0.300
WSO2 Identity Server>=5.11.0<5.11.0.329
WSO2 Identity Server>=6.0.0<6.0.0.179
WSO2 Identity Server>=6.1.0<6.1.0.136
WSO2 Identity Server as Key Manager>=5.10.0<5.10.0.296
WSO2 Open Banking AM>=2.0.0<2.0.0.328
WSO2 Open Banking Iam>=2.0.0<2.0.0.348

Remediation

Information

Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3255/#solution

Event History

Apr 16, 2026
CVE Published
via MITRE·08:12 AM
Data Sourced
via MITRE·08:12 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-2374?

CVE-2024-2374 has a significant severity due to the potential for arbitrary file read and denial of service attacks.

2

How do I fix CVE-2024-2374?

To fix CVE-2024-2374, update your WSO2 products to the latest versions that have addressed this vulnerability.

3

Which WSO2 products are affected by CVE-2024-2374?

CVE-2024-2374 impacts several WSO2 products including WSO2 API Manager, WSO2 Identity Server, and WSO2 Open Banking solutions.

4

What are the consequences of exploiting CVE-2024-2374?

Exploiting CVE-2024-2374 could lead to unauthorized file access and potentially denial of service for affected WSO2 applications.

5

Is there a workaround for CVE-2024-2374 while waiting for a patch?

Currently, there are no recommended workarounds for CVE-2024-2374 aside from limiting access to affected systems until a patch is applied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203