Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3155 articles · 168089 vulns · 37/41 feeds (7d)
← Back to list
6.5
CVE-2026-12993EXPLOITED
red hat · red hat build of apicurio registry

Apicurio/apicurio-registry: apicurio-registry: xml entity-expansion denial of service via internal dtd subset

Description

A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE declarations or enable FEATURE_SECURE_PROCESSING. An attacker with artifact-write permission can upload XML documents with internal entity-expansion payloads (billion-laughs variant) that cause CPU and heap exhaustion, partially mitigated by the JAXP default 64,000 entity-expansion limit.

Affected Products

VendorProductVersions
red hatred hat build of apicurio registry—

References

  • https://access.redhat.com/security/cve/CVE-2026-12993(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2491692(issue-tracking, x_refsource_REDHAT)

Related News (1 articles)

Tier C
VulDB2d ago
CVE-2026-12993 | Red Hat Apicurio Registry 3 XML Document xml entity expansion
→ No new info (linked only)
CVSS 3.16.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-776
PublishedJun 25, 2026
Last enriched1d agov2
Trending Score36
Source articles1
Independent1
Info Completeness7/14
Missing: versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-9800EXP
Keycloak: keycloak policy enforcer: authorization bypass via incorrect uri comparison
Trending: 45
NONECVE-2026-9086EXP
Keycloak: keycloak: cross-site scripting (xss) via case-insensitive uri validation bypass
Trending: 45
NONECVE-2026-9083EXP
Keycloak: keycloak: information disclosure through arbitrary filesystem path probing
Trending: 41
CRITICALCVE-2026-12992EXP
Apicurio/apicurio-registry: apicurio-registry: ssrf via wsdl4j import dereference in wsdl full validation
Trending: 38
NONECVE-2026-13325EXP
Virt-handler-rhel9: kubevirt: kubevirt: disabletls migration setting removes authentication, exposing unauthenticated virtqemud proxy on all interfaces
Trending: 36

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 25, 2026
Actively Exploited
Jun 26, 2026
Discovered by ZDM
Jun 26, 2026
Updated: severity, activelyExploited
Jun 26, 2026

Version History

v2
Last enriched 1d ago
v2Tier C1d ago

Updated vendor to Red Hat, product to Red Hat Apicurio Registry 3, severity to HIGH, and marked as actively exploited.

severityactivelyExploited
via VulDB
v12d ago

Initial creation