CVE-2026-61586: XEE
Copernik XML Factory through 0.1.1, when running on its stock JDK provider, does not block XInclude resource resolution after an application enables XInclude on a factory returned by XmlFactories.newDocumentBuilderFactory() or XmlFactories.newSAXParserFactory(), or on an XMLReader passed through XmlFactories.harden(). The library's documented guarantee that XInclude resolution stays disabled therefore does not hold on that provider.
An application that parses untrusted XML in this configuration can be made to resolve xi:include references, allowing an attacker to read local files (information disclosure) or, through http hrefs, reach internal network endpoints (SSRF).
All of the following conditions must hold for an application to be affected: - it obtains a factory from XmlFactories.newDocumentBuilderFactory() or XmlFactories.newSAXParserFactory(), or hardens an externally obtained XMLReader with XmlFactories.harden(); - the stock JDK provider is in effect, that is, Apache Xerces is not on the classpath; - XInclude is enabled, by calling setXIncludeAware(true) or the equivalent reader feature; - it parses XML from an untrusted source.
The Xerces provider (selected when Xerces is on the classpath) and the Android provider are not affected.
Applications are advised to upgrade to 0.1.2, which fixes the defect. As a workaround add Apache Xerces (xercesImpl) to the classpath so the library selects its unaffected Xerces provider.
Acknowledgements
The maintainer thank the following people for finding, reporting, and helping to remediate this issue:
- Finders: Ta Duc Thien and Duc Anh Nguyen (Danzation) - Remediation developer: Ta Duc Thien - Tooling: Claude Code (Anthropic), Claude Opus 4.8
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/eu.copernik:copernik-xml-factoryto a version that resolves this vulnerability.Fixed in 0.1.2 - Upgrade
Upgrade
Copernik XML Factoryto a version that resolves this vulnerability.Fixed in 0.1.2 - Configuration
Add Apache Xerces (xercesImpl) to the classpath so the library selects the unaffected Xerces provider.
Copernik XML Factory XML provider classpath = Apache Xerces (xercesImpl)
Event History
Frequently Asked Questions
How can I determine whether an application is exposed?
Check whether it uses a factory returned by XmlFactories.newDocumentBuilderFactory() or XmlFactories.newSAXParserFactory(), or passes an XMLReader through XmlFactories.harden(). It is exposed only if the stock JDK provider is in use without Apache Xerces on the classpath, XInclude has been enabled, and the parser accepts untrusted XML.
Is an application affected if it does not enable XInclude?
No. Enabling XInclude through setXIncludeAware(true) or the equivalent XMLReader feature is a required condition for this issue.
What can be done if remediation cannot be applied immediately?
Do not enable XInclude for parsers that process untrusted XML. If XInclude is required, avoid parsing XML from untrusted sources until the affected configuration can be remediated.