CVE-2026-3415

Summary

The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validation flows. Under certain conditions, the XML parser allows the resolution of external entities when handling user-supplied XML content during validation operations. This behavior can occur when an attacker supplies crafted XML payloads to the relevant mediator flows with sufficient privileges.

Successful exploitation may allow a highly privileged actor to read files accessible within the server hosting the affected product. Additionally, it may be possible to trigger outbound requests to unintended internal or external locations, depending on the server environment and network configuration. Specially crafted XML payloads can also lead to excessive resource consumption during parsing, impacting the availability of the product.

Affected Software

VendorProductVersion RangeStatus
WSO2WSO2 API Manager0 < 3.2.0unknown
WSO2WSO2 API Manager3.2.0 < 3.2.0.472affected
WSO2WSO2 API Manager3.2.1 < 3.2.1.91affected
WSO2WSO2 API Manager4.1.0 < 4.1.0.254affected
WSO2WSO2 API Manager4.2.0 < 4.2.0.194affected
WSO2WSO2 API Manager4.3.0 < 4.3.0.105affected
WSO2WSO2 API Manager4.4.0 < 4.4.0.68affected
WSO2WSO2 API Manager4.5.0 < 4.5.0.53affected
WSO2WSO2 API Manager4.6.0 < 4.6.0.16affected
WSO2WSO2 Universal Gateway4.5.0 < 4.5.0.53affected
WSO2WSO2 Universal Gateway4.6.0 < 4.6.0.16affected
WSO2WSO2 Traffic Manager4.5.0 < 4.5.0.52affected
WSO2WSO2 Traffic Manager4.6.0 < 4.6.0.16affected
WSO2WSO2 API Control Plane4.5.0 < 4.5.0.54affected
WSO2WSO2 API Control Plane4.6.0 < 4.6.0.17affected
WSO2WSO2 Carbon API Gateway6.7.206 < 6.7.206.594affected
WSO2WSO2 Carbon API Gateway6.7.210 < 6.7.210.95affected
WSO2WSO2 Carbon API Gateway9.20.74 < 9.20.74.398affected
WSO2WSO2 Carbon API Gateway9.28.116 < 9.28.116.412affected
WSO2WSO2 Carbon API Gateway9.29.120 < 9.29.120.228affected
WSO2WSO2 Carbon API Gateway9.30.67 < 9.30.67.158affected
WSO2WSO2 Carbon API Gateway9.31.86 < 9.31.86.147affected
WSO2WSO2 Carbon API Gateway9.32.147 < 9.32.147.38affected
WSO2WSO2 Carbon API Gateway9.33.61 <= *unaffected
WSO2WSO2 Carbon API Management Implementation6.7.206 < 6.7.206.594affected
WSO2WSO2 Carbon API Management Implementation6.7.210 < 6.7.210.95affected
WSO2WSO2 Carbon API Management Implementation9.20.74 < 9.20.74.398affected
WSO2WSO2 Carbon API Management Implementation9.28.116 < 9.28.116.412affected
WSO2WSO2 Carbon API Management Implementation9.29.120 < 9.29.120.228affected
WSO2WSO2 Carbon API Management Implementation9.30.67 < 9.30.67.158affected
WSO2WSO2 Carbon API Management Implementation9.31.86 < 9.31.86.147affected
WSO2WSO2 Carbon API Management Implementation9.32.147 < 9.32.147.38affected
WSO2WSO2 Carbon API Management Implementation9.33.61 <= *unaffected

Weaknesses

  • CWE-776: CWE-776: Improper Handling of Special Elements in XML Document Type Declaration (DTD)

References