Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 29 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 26 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 25 Jun 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE declarations or enable FEATURE_SECURE_PROCESSING. An attacker with artifact-write permission can upload XML documents with internal entity-expansion payloads (billion-laughs variant) that cause CPU and heap exhaustion, partially mitigated by the JAXP default 64,000 entity-expansion limit. | |
| Title | Apicurio/apicurio-registry: apicurio-registry: xml entity-expansion denial of service via internal dtd subset | |
| First Time appeared |
Redhat
Redhat apicurio Registry |
|
| Weaknesses | CWE-776 | |
| CPEs | cpe:/a:redhat:apicurio_registry:3 | |
| Vendors & Products |
Redhat
Redhat apicurio Registry |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-06-29T18:12:24.123Z
Reserved: 2026-06-23T12:18:15.412Z
Link: CVE-2026-12993
Updated: 2026-06-29T18:12:18.774Z
No data.
OpenCVE Enrichment
Updated: 2026-06-26T09:36:05Z