GHSA-6fhj-vr9j-g45r
HIGHCVE-2025-64518The XML [Validator](https://docs.oracle.com/javase/8/docs/api/javax/xml/validation/Validator.html) used by cyclonedx-core-java was not configured securely, making the library vulnerable to XML External Entity (XXE) injection.
- Affected
- >= 2.1.0, < 11.0.1
- Fixed in
- 11.0.1
- Weakness
- CWE-611
- Published
- 2025-11-10
- Source
- github