CVE-2026-61586: XEE

Published Oct 2, 2026
·
Updated

Copernik XML Factory through 0.1.1, when running on its stock JDK provider, does not block XInclude resource resolution after an application enables XInclude on a factory returned by XmlFactories.newDocumentBuilderFactory() or XmlFactories.newSAXParserFactory(), or on an XMLReader passed through XmlFactories.harden(). The library's documented guarantee that XInclude resolution stays disabled therefore does not hold on that provider.

An application that parses untrusted XML in this configuration can be made to resolve xi:include references, allowing an attacker to read local files (information disclosure) or, through http hrefs, reach internal network endpoints (SSRF).

All of the following conditions must hold for an application to be affected: - it obtains a factory from XmlFactories.newDocumentBuilderFactory() or XmlFactories.newSAXParserFactory(), or hardens an externally obtained XMLReader with XmlFactories.harden(); - the stock JDK provider is in effect, that is, Apache Xerces is not on the classpath; - XInclude is enabled, by calling setXIncludeAware(true) or the equivalent reader feature; - it parses XML from an untrusted source.

The Xerces provider (selected when Xerces is on the classpath) and the Android provider are not affected.

Applications are advised to upgrade to 0.1.2, which fixes the defect. As a workaround add Apache Xerces (xercesImpl) to the classpath so the library selects its unaffected Xerces provider.

Acknowledgements

The maintainer thank the following people for finding, reporting, and helping to remediate this issue:

- Finders: Ta Duc Thien and Duc Anh Nguyen (Danzation) - Remediation developer: Ta Duc Thien - Tooling: Claude Code (Anthropic), Claude Opus 4.8

Affected Software

1 affected componentFixes available
maven/eu.copernik:copernik-xml-factory<0.1.2
0.1.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/eu.copernik:copernik-xml-factory to a version that resolves this vulnerability.

    Fixed in 0.1.2
  2. Upgrade

    Upgrade Copernik XML Factory to a version that resolves this vulnerability.

    Fixed in 0.1.2
  3. Configuration

    Add Apache Xerces (xercesImpl) to the classpath so the library selects the unaffected Xerces provider.

    Copernik XML Factory XML provider classpath = Apache Xerces (xercesImpl)

Event History

Oct 2, 2026
Advisory Published
via GitHub·06:27 PM
Data Sourced
via GitHub·06:27 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

How can I determine whether an application is exposed?

Check whether it uses a factory returned by XmlFactories.newDocumentBuilderFactory() or XmlFactories.newSAXParserFactory(), or passes an XMLReader through XmlFactories.harden(). It is exposed only if the stock JDK provider is in use without Apache Xerces on the classpath, XInclude has been enabled, and the parser accepts untrusted XML.

2

Is an application affected if it does not enable XInclude?

No. Enabling XInclude through setXIncludeAware(true) or the equivalent XMLReader feature is a required condition for this issue.

3

What can be done if remediation cannot be applied immediately?

Do not enable XInclude for parsers that process untrusted XML. If XInclude is required, avoid parsing XML from untrusted sources until the affected configuration can be remediated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203