CVE-2026-19614: XML External Entity (XXE) Injection in CyberELF NanoXML
Published Sep 8, 2026
·Updated
The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3.
Affected Software
1 affected component
CyberELF NanoXML=2.2.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NanoXMLto a version that resolves this vulnerability.Fixed in 2.2.3 - Configuration
Disable XML external entity (XXE) support because XXE support is enabled by default and the API is prone to XXE injection in NanoXML 2.2.3.
NanoXML XML external entity (XXE) support = disabled
Event History
Sep 8, 2026
CVE Published
via MITRE·10:28 AM
Data Sourced
via MITRE·10:28 AM
DescriptionWeakness
Frequently Asked Questions
1
Is a default NanoXML 2.2.3 deployment affected?
Yes. XML external entity support is enabled by default in NanoXML 2.2.3, so deployments using the default XML-processing configuration are affected.
2
What configuration change can reduce exposure if patching is not immediately possible?
Disable XML external entity support. The issue is tied to external entity processing being enabled.