Disclosure summary
Copernik XML Factory through `0.1.1`, when running on its stock JDK provider, does not block XInclude resource resolution after an application enables XInclude on a factory returned by `XmlFactories.newDocumentBuilderFactory()` or `XmlFactories.newSAXParserFactory()`, or on an `XMLReader` passed through `XmlFactories.harden()`. The library's documented guarantee that XInclude resolution stays disabled therefore does not hold on that provider. An application that parses untrusted XML in this configuration can be made to resolve `xi:include` references, allowing an attacker to read local files (information disclosure) or, through `http` hrefs, reach internal network endpoints (SSRF). All of the following conditions must hold for an application to be affected: - it obtains a factory from `XmlFactories.newDocumentBuilderFactory()` or `XmlFactories.newSAXParserFactory()`, or hardens an externally obtained `XMLReader` with `XmlFactories.harden()`; - the stock JDK provider is in effect, that is, Apache Xerces is not on the classpath; - XInclude is enabled, by calling `setXIncludeAware(true)` or the equivalent reader feature; - it parses XML from an untrusted source. The Xerces provider (s
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-xm28-xvqc-gxxg
Open original source · Updated Oct 02, 2026
Copernik XML Factory (stock JDK provider) has Improper restriction of XInclude resource resolution
Source severity: HIGH / 8.2
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| maven | eu.copernik:copernik-xml-factory | < 0.1.2 | 0.1.2 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-02T14:27:17-04:00
MODIFIED 2026-10-02T14:27:20-04:00
INGESTED 2026-10-06T11:45:17-04:00