{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49875.json"
      }
    ],
    "title": "cxf: org.apache.cxf/cxf-core: Apache CXF: Information disclosure via out-of-band external entity resolution due to missing JAXP hardening",
    "tracking": {
      "current_release_date": "2026-07-27T12:46:59+00:00",
      "generator": {
        "date": "2026-07-27T12:46:59+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.7"
        }
      },
      "id": "CVE-2026-49875",
      "initial_release_date": "2026-06-12T08:54:50.103000+00:00",
      "revision_history": [
        {
          "date": "2026-06-12T08:54:50.103000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-27T09:12:43+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-07-27T12:46:59+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat build of Apache Camel 4 for Quarkus 3",
                "product": {
                  "name": "Red Hat build of Apache Camel 4 for Quarkus 3",
                  "product_id": "red_hat_build_of_apache_camel_4_for_quarkus_3",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:camel_quarkus:3"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat build of Apache Camel 4 for Quarkus 3"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Fuse 7",
                "product": {
                  "name": "Red Hat Fuse 7",
                  "product_id": "red_hat_fuse_7",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_fuse:7"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Fuse 7"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Enterprise Application Platform 7",
                "product": {
                  "name": "Red Hat JBoss Enterprise Application Platform 7",
                  "product_id": "red_hat_jboss_enterprise_application_platform_7",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:7"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Enterprise Application Platform 7"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Enterprise Application Platform 8",
                "product": {
                  "name": "Red Hat JBoss Enterprise Application Platform 8",
                  "product_id": "red_hat_jboss_enterprise_application_platform_8",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:8"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Enterprise Application Platform 8"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
                "product": {
                  "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
                  "product_id": "red_hat_jboss_enterprise_application_platform_expansion_pack",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jbosseapxp"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Web Server 5",
                "product": {
                  "name": "Red Hat JBoss Web Server 5",
                  "product_id": "red_hat_jboss_web_server_5",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:5"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Web Server 5"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Single Sign-On 7",
                "product": {
                  "name": "Red Hat Single Sign-On 7",
                  "product_id": "red_hat_single_sign-on_7",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:red_hat_single_sign_on:7"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Single Sign-On 7"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16",
                "product": {
                  "name": "Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16",
                  "product_id": "Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:apache_camel_spring_boot:4.18"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "Red Hat Build of Apache Camel 4.18 for Quarkus 3.33",
                "product": {
                  "name": "Red Hat Build of Apache Camel 4.18 for Quarkus 3.33",
                  "product_id": "Red Hat Build of Apache Camel 4.18 for Quarkus 3.33",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:apache_camel_quarkus:3.33"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Build of Apache Camel"
          },
          {
            "category": "product_version",
            "name": "cxf-core",
            "product": {
              "name": "cxf-core",
              "product_id": "cxf-core",
              "product_identification_helper": {
                "purl": "pkg:maven/org.apache.cxf/cxf-core"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cxf-core as a component of Red Hat build of Apache Camel 4 for Quarkus 3",
          "product_id": "red_hat_build_of_apache_camel_4_for_quarkus_3:cxf-core"
        },
        "product_reference": "cxf-core",
        "relates_to_product_reference": "red_hat_build_of_apache_camel_4_for_quarkus_3"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cxf-core as a component of Red Hat Fuse 7",
          "product_id": "red_hat_fuse_7:cxf-core"
        },
        "product_reference": "cxf-core",
        "relates_to_product_reference": "red_hat_fuse_7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cxf-core as a component of Red Hat JBoss Enterprise Application Platform 7",
          "product_id": "red_hat_jboss_enterprise_application_platform_7:cxf-core"
        },
        "product_reference": "cxf-core",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cxf-core as a component of Red Hat JBoss Enterprise Application Platform 8",
          "product_id": "red_hat_jboss_enterprise_application_platform_8:cxf-core"
        },
        "product_reference": "cxf-core",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cxf-core as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack",
          "product_id": "red_hat_jboss_enterprise_application_platform_expansion_pack:cxf-core"
        },
        "product_reference": "cxf-core",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_expansion_pack"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cxf-core as a component of Red Hat JBoss Web Server 5",
          "product_id": "red_hat_jboss_web_server_5:cxf-core"
        },
        "product_reference": "cxf-core",
        "relates_to_product_reference": "red_hat_jboss_web_server_5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cxf-core as a component of Red Hat Single Sign-On 7",
          "product_id": "red_hat_single_sign-on_7:cxf-core"
        },
        "product_reference": "cxf-core",
        "relates_to_product_reference": "red_hat_single_sign-on_7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-49875",
      "cwe": {
        "id": "CWE-611",
        "name": "Improper Restriction of XML External Entity Reference"
      },
      "discovery_date": "2026-06-12T10:01:23.698724+00:00",
      "flags": [
        {
          "label": "component_not_present",
          "product_ids": [
            "red_hat_jboss_enterprise_application_platform_expansion_pack:cxf-core"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2488309"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Apache CXF. The EndpointReferenceUtils and W3CMultiSchemaFactory classes within Apache CXF construct a SAXParserFactory without proper security configurations. This oversight enables out-of-band (OOB) external entity resolution, a type of XML External Entity (XXE) vulnerability. A remote attacker could exploit this to disclose sensitive information from the affected system.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "cxf: org.apache.cxf/cxf-core: Apache CXF: Information disclosure via out-of-band external entity resolution due to missing JAXP hardening",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This is an Important information disclosure vulnerability in Apache CXF, affecting Red Hat products that bundle the component, such as Enterprise Application Platform, JBoss Web Server, and Red Hat Single Sign-On. The flaw allows a remote attacker to disclose sensitive information due to improper XML parsing configurations, which can be exploited without user interaction.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Build of Apache Camel 4.18 for Quarkus 3.33",
          "Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16"
        ],
        "known_affected": [
          "red_hat_build_of_apache_camel_4_for_quarkus_3:cxf-core",
          "red_hat_fuse_7:cxf-core",
          "red_hat_jboss_enterprise_application_platform_7:cxf-core",
          "red_hat_jboss_enterprise_application_platform_8:cxf-core",
          "red_hat_jboss_web_server_5:cxf-core",
          "red_hat_single_sign-on_7:cxf-core"
        ],
        "known_not_affected": [
          "red_hat_jboss_enterprise_application_platform_expansion_pack:cxf-core"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-49875"
        },
        {
          "category": "external",
          "summary": "RHBZ#2488309",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2488309"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-49875",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-49875"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-49875",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49875"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/06/11/2",
          "url": "http://www.openwall.com/lists/oss-security/2026/06/11/2"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/3kb9w5bg90xcp06fccoz9k3gpsvyy79o",
          "url": "https://lists.apache.org/thread/3kb9w5bg90xcp06fccoz9k3gpsvyy79o"
        }
      ],
      "release_date": "2026-06-12T08:54:50.103000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-08T18:28:22+00:00",
          "details": "Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.\nThe References section of this erratum contains a download link (you must log in to download the update).",
          "product_ids": [
            "Red Hat Build of Apache Camel 4.18 for Quarkus 3.33"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2026:36839"
        },
        {
          "category": "vendor_fix",
          "date": "2026-07-09T15:29:15+00:00",
          "details": "Before applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2026:37390"
        },
        {
          "category": "workaround",
          "details": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
          "product_ids": [
            "Red Hat Build of Apache Camel 4.18 for Quarkus 3.33",
            "Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16",
            "red_hat_build_of_apache_camel_4_for_quarkus_3:cxf-core",
            "red_hat_fuse_7:cxf-core",
            "red_hat_jboss_enterprise_application_platform_7:cxf-core",
            "red_hat_jboss_enterprise_application_platform_8:cxf-core",
            "red_hat_jboss_web_server_5:cxf-core",
            "red_hat_single_sign-on_7:cxf-core"
          ]
        },
        {
          "category": "none_available",
          "details": "Fix deferred",
          "product_ids": [
            "red_hat_fuse_7:cxf-core",
            "red_hat_jboss_enterprise_application_platform_7:cxf-core",
            "red_hat_jboss_web_server_5:cxf-core",
            "red_hat_single_sign-on_7:cxf-core"
          ]
        },
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "red_hat_build_of_apache_camel_4_for_quarkus_3:cxf-core",
            "red_hat_jboss_enterprise_application_platform_8:cxf-core"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "Red Hat Build of Apache Camel 4.18 for Quarkus 3.33",
            "Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16",
            "red_hat_build_of_apache_camel_4_for_quarkus_3:cxf-core",
            "red_hat_fuse_7:cxf-core",
            "red_hat_jboss_enterprise_application_platform_7:cxf-core",
            "red_hat_jboss_enterprise_application_platform_8:cxf-core",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:cxf-core",
            "red_hat_jboss_web_server_5:cxf-core",
            "red_hat_single_sign-on_7:cxf-core"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "Red Hat Build of Apache Camel 4.18 for Quarkus 3.33",
            "Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16",
            "red_hat_build_of_apache_camel_4_for_quarkus_3:cxf-core",
            "red_hat_fuse_7:cxf-core",
            "red_hat_jboss_enterprise_application_platform_7:cxf-core",
            "red_hat_jboss_enterprise_application_platform_8:cxf-core",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:cxf-core",
            "red_hat_jboss_web_server_5:cxf-core",
            "red_hat_single_sign-on_7:cxf-core"
          ]
        }
      ],
      "title": "cxf: org.apache.cxf/cxf-core: Apache CXF: Information disclosure via out-of-band external entity resolution due to missing JAXP hardening"
    }
  ]
}