Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Cloud Discovery Service, Recording Service, Routing Service, Queueing Service, Observability Collector) allows Serialized Data External Linking, Data Serialization External Entities Blowup.<p>This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.1.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*.</p>
References
| Link | Resource |
|---|---|
| https://www.rti.com/vulnerabilities/#cve-2026-4374 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
17 Jun 2026, 19:18
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Cloud Discovery Service, Recording Service, Routing Service, Queueing Service, Observability Collector) allows Serialized Data External Linking, Data Serialization External Entities Blowup.<p>This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.1.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*.</p> |
21 Apr 2026, 00:06
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
| CPE | cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:* | |
| Summary |
|
|
| First Time |
Rti connext Professional
Rti |
|
| References | () https://www.rti.com/vulnerabilities/#cve-2026-4374 - Vendor Advisory |
01 Apr 2026, 02:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-01 02:16
Updated : 2026-06-17 19:18
NVD link : CVE-2026-4374
Mitre link : CVE-2026-4374
CVE.ORG link : CVE-2026-4374
JSON object : View
Products Affected
rti
- connext_professional
CWE
CWE-611
Improper Restriction of XML External Entity Reference
