CWE-112Base

Missing XML Validation

Draft in the CWE catalog · 7 CVEs mapped

7
CVEs mapped
6.3
Median CVSS
What it is

The product accepts XML from an untrusted source but does not validate the XML against the proper schema.

Recent examples
3.1cvss
CVE-2026-1190

Org.keycloak/keycloak-services: keycloak saml brokering: response delay due to unchecked notonorafter in subjectconfirmationdata

A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Assertion Markup Language (SAML) setup, it fails to validate the `NotOnOrAfter` timestamp within the `SubjectConfirmationData`. This allows an attacker to delay the expiration of SAML responses, potentially extending the time a response is considered valid and leading to unexpected session durations or resource consumption.

LOWno explanation yet
0%
epss
6.5cvss
CVE-2023-40310

Missing XML Validation vulnerability in SAP PowerDesigner Client BPMN2 import

SAP PowerDesigner Client - version 16.7, does not sufficiently validate BPMN2 XML document imported from an untrusted source. As a result, URLs of external entities in BPMN2 file, although not used, would be accessed during import. A successful attack could impact availability of SAP PowerDesigner Client.

MEDIUMno explanation yet
1%
epss
5.3cvss
CVE-2021-27780

HCL BigFix Mobile / Modern Client Management is vulnerable to unauthenticated XML interaction

The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.

MEDIUMno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-112
Abstraction
Base
Structure
Simple
Status
Draft
References (1)