CVE WATCH / VULNERABILITY DETAIL
CVE-2026-88789
HIGHCVSS 8.6NVD feed
Published 1 October 2026 · tracked since 2 October 2026
Description
Improper Restriction of XML External Entity Reference in the XSLT support extension (camel-quarkus-support-xalan) in Apache Camel Quarkus from 3.2.0 before 3.33.3 and from 3.34.0 before 3.40.0 on all platforms allows an attacker who supplies the XML document being transformed to read local files or
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog