CVE-2026-12993

A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE declarations or enable FEATURE_SECURE_PROCESSING. An attacker with artifact-write permission can upload XML documents with internal entity-expansion payloads (billion-laughs variant) that cause CPU and heap exhaustion, partially mitigated by the JAXP default 64,000 entity-expansion limit.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:build_of_apicurio_registry:*:*:*:*:*:*:*:*

History

06 Jul 2026, 18:12

Type Values Removed Values Added
CPE cpe:2.3:a:redhat:build_of_apicurio_registry:*:*:*:*:*:*:*:*
First Time Redhat build Of Apicurio Registry
Redhat
References () https://access.redhat.com/security/cve/CVE-2026-12993 - () https://access.redhat.com/security/cve/CVE-2026-12993 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2491692 - () https://bugzilla.redhat.com/show_bug.cgi?id=2491692 - Issue Tracking, Vendor Advisory

26 Jun 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-26 00:16

Updated : 2026-07-06 18:12


NVD link : CVE-2026-12993

Mitre link : CVE-2026-12993

CVE.ORG link : CVE-2026-12993


JSON object : View

Products Affected

redhat

  • build_of_apicurio_registry
CWE
CWE-776

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')