High
nvd
·
CVE-2026-82578
CVE-2026-82578: When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPat
Published Sep 11, 2026
CVSS 8.7
When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks.
Affected AI Products
jax