CVE-2026-38165: Xdocreport vulnerability
A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
xdocreportto a version that resolves this vulnerability.Fixed in v2.2.0 - Compensating control
Apply compensating controls to limit exposure to the vulnerable Velocity template engine configuration until patched (e.g., restrict/validate any input that is used to render templates, and ensure only trusted template expressions can be processed).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-38165?
The severity of CVE-2026-38165 is rated at 81, indicating a high risk of exploitation.
How do I fix CVE-2026-38165?
To fix CVE-2026-38165, update the xdocreport library to a version higher than 2.2.0.
What type of vulnerability is CVE-2026-38165?
CVE-2026-38165 is classified as a Server-Side Template Injection (SSTI) vulnerability.
What can attackers do with CVE-2026-38165?
Attackers can execute arbitrary code on the server through a crafted expression due to CVE-2026-38165.
Which versions of xdocreport are affected by CVE-2026-38165?
The affected versions of xdocreport are from v0.9.2 to v2.2.0.