Search/CVE-2021-40690
CVE — High

CVE-2021-40690

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

CVSS v3.1
7.5 HIGH
EPSS
7.38%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
Timeline
disclosure → media coverage
Sep 19, 2021
Disclosure — published as a CVE record. · last revised by NVD Aug 25, 2026