CVE-2026-19614

Summary

The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3.

Affected Software

VendorProductVersion RangeStatus
CyberELFNanoXML2.2.3affected

Weaknesses

  • CWE-611: CWE-611 Improper restriction of XML external entity reference

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References