Apache disclosed CVE-2026-88789, a high-severity XXE flaw (CVSS 8.6, CWE-611) in the camel-quarkus-support-xalan XSLT extension. The extension forces legacy Xalan-J 2.7.x as the default JAXP TransformerFactory, which does not honor Camel’s external-DTD and stylesheet access restrictions. An unauthenticated attacker able to provide XML for transformation as a javax.xml.transform.Source could use external entities to read local files or induce requests to internal network services. Versions 3.2.0 through 3.33.2 and 3.34.0 through 3.39.x are affected; XML bodies converted to hardened SAXSource objects are not on the directly affected path.
Camel Quarkus fixed the issue in versions 3.33.3 and 3.40.0 by enforcing parser-level blocks on external general entities, external parameter entities, and external DTDs within its Xalan transformer factory. The fix also denies XSLT document() resource retrieval unless an application-provided URIResolver explicitly authorizes it, while retaining application and per-exchange resolver behavior. Organizations using affected releases should upgrade promptly and review direct use of TransformerFactory.newInstance() and any intentionally configured URI resolvers; XSLT xsl:import and xsl:include remain outside these specific runtime controls because Xalan resolves them during stylesheet compilation.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-88789 was published as a high-severity CWE-611 XXE vulnerability affecting camel-quarkus-support-xalan versions before 3.33.3 in the 3.2.x–3.33.x line and before 3.40.0 in the 3.34.x–3.39.x line. An unauthenticated attacker able to provide XML for transformation as a Source could read local files or trigger internal-network requests; Apache recommended upgrading to 3.33.3 or 3.40.0.
Commit 9dd1177 extended the Xalan transformer hardening to disable external parameter entities and external DTD loading, complementing the existing block on external general entities. Tests verified that external DTDs and parameter entities could not inject data into transformation results.
James Netherton opened issue #9115, identifying that the XSLT extension's custom TransformerFactory did not inherit Apache Camel's restrictions on external DTD and stylesheet access. The issue proposed applying equivalent restrictions within the extension.
Apache Camel Quarkus backported the XSLT external-entity and resource-access fixes to the 3.33.x branch in commits ad9c52365dc85eac029e8bfe3899aee07e48a525 and 3d8867697c105c0d648fdcfe07f8dd7159cb3d47.
Apache Camel Quarkus updated its XSLT extension to prevent external general-entity resolution in XML parsed during transformations and to deny XSLT document() retrieval unless an application-provided URIResolver permits it. The changes compensate for Xalan-J 2.7.x not honoring JAXP external-access controls.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourceopenwall.com
Open sourcecamel.apache.org
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.