Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3442 articles · 168416 vulns · 37/41 feeds (7d)
← Back to list
7.4
CVE-2026-12992EXPLOITED
red hat · red hat build of apicurio registry

Apicurio/apicurio-registry: apicurio-registry: ssrf via wsdl4j import dereference in wsdl full validation

Description

A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. When the VALIDITY rule is set to FULL, an attacker with Developer-role access can upload a WSDL document containing attacker-controlled import locations, causing the registry to issue HTTP requests to arbitrary internal URLs (server-side request forgery).

Affected Products

VendorProductVersions
red hatred hat build of apicurio registry—

References

  • https://access.redhat.com/security/cve/CVE-2026-12992(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2491691(issue-tracking, x_refsource_REDHAT)

Related News (1 articles)

Tier C
VulDB2d ago
CVE-2026-12992 | Red Hat Apicurio Registry 3 Documents Feature javax.wsdl server-side request forgery
→ No new info (linked only)
CVSS 3.17.4 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-918
PublishedJun 25, 2026
Last enriched2d agov2
Tags
CVE-2026-12992
Trending Score33
Source articles1
Independent1
Info Completeness7/14
Missing: versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-9800EXP
Keycloak: keycloak policy enforcer: authorization bypass via incorrect uri comparison
Trending: 39
NONECVE-2026-9086EXP
Keycloak: keycloak: cross-site scripting (xss) via case-insensitive uri validation bypass
Trending: 39
NONECVE-2026-55653
Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service
Trending: 35
NONECVE-2026-55655
Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions
Trending: 35
NONECVE-2026-9083EXP
Keycloak: keycloak: information disclosure through arbitrary filesystem path probing
Trending: 35

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 25, 2026
Discovered by ZDM
Jun 25, 2026
Actively Exploited
Jun 25, 2026
Updated: severity, activelyExploited, tags
Jun 26, 2026

Version History

v2
Last enriched 2d ago
v2Tier C2d ago

Updated severity to CRITICAL, marked as actively exploited, and added new tag CVE-2026-12992.

severityactivelyExploitedtags
via VulDB
v12d ago

Initial creation