Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3191 articles · 168085 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2024-2374PATCHED
wso2 · api manager

XML External Entity Injection in Multiple WSO2 Products Allows Arbitrary file read and Denial of Service

Description

The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entities. This omission allows malicious actors to craft XML payloads that exploit the parser's behavior, leading to the inclusion of external resources. By leveraging this vulnerability, an attacker can read confidential files from the file system and access limited HTTP resources reachable by the product. Additionally, the vulnerability can be exploited to perform denial of service attacks by exhausting server resources through recursive entity expansion or fetching large external resources.

Affected Products

VendorProductVersions
wso2api manager3.1.0, 3.2.0, 4.0.0, 4.1.0, 4.2.0, 4.3.0, 5.10.0, 5.11.0, 6.0.0, 6.1.0, 2.0.0, 2.0.0, 5.10.0

References

  • https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2024-3255/(vendor-advisory)

Related News (1 articles)

Tier C
VulDB72d ago
CVE-2024-2374 | WSO2 API Manager XML Parser xml external entity reference
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
3.1.0.2783.2.0.3684.0.0.2804.1.0.2064.2.0.1444.3.0.575.10.0.3005.11.0.3296.0.0.1796.1.0.1362.0.0.3282.0.0.3485.10.0.296
CWECWE-611
PublishedApr 16, 2026
Last enriched72d agov2
Trending Score0
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-2053EXP
Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Manager
Trending: 54
HIGHCVE-2025-10908EXP
Account Lock Bypass via Magic Link or Pass Key Authentication in WSO2 Identity Server Allows Unauthorized Access
MEDIUMCVE-2024-0391EXP
Username Enumeration via Email OTP Flow in Multiple WSO2 Products Allows User Account Discovery
MEDIUMCVE-2025-9973
Authorization Bypass via Adaptive Authentication in WSO2 Identity Server Allows Cross-Organization Account Takeover
MEDIUMCVE-2025-8325EXP
Improper Access Control via Gateway API in Multiple WSO2 Products Allows Unauthorized Operations

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 16, 2026
Discovered by ZDM
Apr 16, 2026
Updated: severity
Apr 16, 2026
Patch Available
Apr 16, 2026

Version History

v2
Last enriched 72d ago
v2Tier C72d ago

Updated product list to include additional WSO2 components and changed severity to MEDIUM with no exploit available.

severity
via VulDB
v172d ago

Initial creation