Beveiligingsadvies

CVE-2026-12992

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-25 21:16:11
Laatst bijgewerkt 2026-08-26 12:04:56
Toegewezen door redhat
CVSS-score 7.4
Status PUBLISHED

Beschrijving

A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. When the VALIDITY rule is set to FULL, an attacker with Developer-role access can upload a WSDL document containing attacker-controlled import locations, causing the registry to issue HTTP requests to arbitrary internal URLs (server-side request forgery).