CVE-2026-49875
Apache Software Foundation Apache CXF, Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16, Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 취약점
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.
- 대응 우선순위
- 점검
- CVSS
- 9.8
- EPSS
- 0.53% 백분위 41.7% · 2026.07.31 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.06.12