GHSA-xm28-xvqc-gxxg: XEE

Published Oct 2, 2026
·
Updated

Copernik XML Factory through 0.1.1, when running on its stock JDK provider, does not block XInclude resource resolution after an application enables XInclude on a factory returned by XmlFactories.newDocumentBuilderFactory() or XmlFactories.newSAXParserFactory(), or on an XMLReader passed through XmlFactories.harden(). The library's documented guarantee that XInclude resolution stays disabled therefore does not hold on that provider.

An application that parses untrusted XML in this configuration can be made to resolve xi:include references, allowing an attacker to read local files (information disclosure) or, through http hrefs, reach internal network endpoints (SSRF).

All of the following conditions must hold for an application to be affected: - it obtains a factory from XmlFactories.newDocumentBuilderFactory() or XmlFactories.newSAXParserFactory(), or hardens an externally obtained XMLReader with XmlFactories.harden(); - the stock JDK provider is in effect, that is, Apache Xerces is not on the classpath; - XInclude is enabled, by calling setXIncludeAware(true) or the equivalent reader feature; - it parses XML from an untrusted source.

The Xerces provider (selected when Xerces is on the classpath) and the Android provider are not affected.

Applications are advised to upgrade to 0.1.2, which fixes the defect. As a workaround add Apache Xerces (xercesImpl) to the classpath so the library selects its unaffected Xerces provider.

Acknowledgements

The maintainer thank the following people for finding, reporting, and helping to remediate this issue:

- Finders: Ta Duc Thien and Duc Anh Nguyen (Danzation) - Remediation developer: Ta Duc Thien - Tooling: Claude Code (Anthropic), Claude Opus 4.8

Affected Software

1 affected componentFixes available
maven/eu.copernik:copernik-xml-factory<0.1.2
0.1.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/eu.copernik:copernik-xml-factory to a version that resolves this vulnerability.

    Fixed in 0.1.2
  2. Upgrade

    Upgrade Copernik XML Factory to a version that resolves this vulnerability.

    Fixed in 0.1.2
  3. Configuration

    Add Apache Xerces (xercesImpl) to the classpath so the library selects the unaffected Xerces provider.

    Copernik XML Factory XML provider = Apache Xerces (xercesImpl)

Event History

Oct 2, 2026
Advisory Published
via GitHub·06:27 PM
Data Sourced
via GitHub·06:27 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed?

Affected deployments use Copernik XML Factory through 0.1.1 with the stock JDK XML provider, without Apache Xerces on the classpath. They must also enable XInclude on a factory returned by the library or on an XMLReader hardened by the library, and parse untrusted XML.

2

What does an attacker need to exploit this issue?

An attacker needs to supply XML that the application will parse after XInclude has been enabled in the affected provider configuration. The XML can use xi:include references to target local files or HTTP endpoints reachable from the application.

3

What can be done if updating is not immediately possible?

Ensure XInclude is not enabled for parsers that process untrusted XML. In particular, do not call setXIncludeAware(true) or enable the equivalent XMLReader feature in the affected stock-JDK-provider configuration.

4

How can I determine whether an application is affected?

Check whether it uses eu.copernik:copernik-xml-factory through version 0.1.1, runs without Apache Xerces on the classpath, and enables XInclude on XmlFactories-created factories or a reader passed to XmlFactories.harden(). Confirm whether those parsers accept XML from untrusted sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203