Home

Description

A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. When the VALIDITY rule is set to FULL, an attacker with Developer-role access can upload a WSDL document containing attacker-controlled import locations, causing the registry to issue HTTP requests to arbitrary internal URLs (server-side request forgery).

PUBLISHED Reserved 2026-06-23 | Published 2026-06-25 | Updated 2026-06-25 | Assigner redhat




HIGH: 7.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

Problem types

Server-Side Request Forgery (SSRF)

Product status

Default status
affected

Default status
affected

Timeline

2026-05-24:Reported to Red Hat.
2026-06-10:Made public.

References

access.redhat.com/security/cve/CVE-2026-12992 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2491691 (RHBZ#2491691) issue-tracking

cve.org (CVE-2026-12992)

nvd.nist.gov (CVE-2026-12992)

Download JSON