AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-61586.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 8.2CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 02, 2026

Disclosure summary

Copernik XML Factory through `0.1.1`, when running on its stock JDK provider, does not block XInclude resource resolution after an application enables XInclude on a factory returned by `XmlFactories.newDocumentBuilderFactory()` or `XmlFactories.newSAXParserFactory()`, or on an `XMLReader` passed through `XmlFactories.harden()`. The library's documented guarantee that XInclude resolution stays disabled therefore does not hold on that provider. An application that parses untrusted XML in this configuration can be made to resolve `xi:include` references, allowing an attacker to read local files (information disclosure) or, through `http` hrefs, reach internal network endpoints (SSRF). All of the following conditions must hold for an application to be affected: - it obtains a factory from `XmlFactories.newDocumentBuilderFactory()` or `XmlFactories.newSAXParserFactory()`, or hardens an externally obtained `XMLReader` with `XmlFactories.harden()`; - the stock JDK provider is in effect, that is, Apache Xerces is not on the classpath; - XInclude is enabled, by calling `setXIncludeAware(true)` or the equivalent reader feature; - it parses XML from an untrusted source. The Xerces provider (s

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-xm28-xvqc-gxxg

Open original source · Updated Oct 02, 2026

Copernik XML Factory (stock JDK provider) has Improper restriction of XInclude resource resolution

Source severity: HIGH / 8.2

EcosystemPackageAffected rangeFirst patched
maveneu.copernik:copernik-xml-factory< 0.1.20.1.2

Original records & references

PUBLISHED 2026-10-02T14:27:17-04:00
MODIFIED 2026-10-02T14:27:20-04:00
INGESTED 2026-10-06T11:45:17-04:00