REDHAT-BUG-2460039: XEE
Published Apr 21, 2026
·Updated
XPath.compile creates a new XPathExpression where xmlSecMgr is null opening up XXE and XEE attacks.
Affected Software
1 affected component
XML Security Library xmlsec
Event History
Apr 21, 2026
Data Sourced
via Red Hat·10:05 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2460039?
The severity of REDHAT-BUG-2460039 is high with a score of 7.
2
What vulnerability does REDHAT-BUG-2460039 expose?
REDHAT-BUG-2460039 exposes applications to XML External Entity (XXE) and XML Entity Expansion (XEE) attacks.
3
How do I fix REDHAT-BUG-2460039?
To fix REDHAT-BUG-2460039, ensure that the xmlSecMgr parameter is properly configured when using XPath.compile.
4
Which software is affected by REDHAT-BUG-2460039?
The affected software is the XML Security Library (xmlsec), specifically related to XPath functionality.
5
What is the description of REDHAT-BUG-2460039?
REDHAT-BUG-2460039 describes an issue where XPath.compile creates a new XPathExpression with a null xmlSecMgr, leading to potential XXE and XEE vulnerabilities.