← Vulnerability feed

Vulnerability record · CVE-2018-1259 · published 11 May 2018

CVE-2018-1259: Broadcom spring data commons xml external entity (xxe) vulnerability

Broadcom · Spring Data Commons

Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.

7.5 CVSS 3.0 High EPSS 4.9% · top 8.2% CWE-611 · XML external entity (XXE)
7.5CVSS 3.0 base score, v2 5.0
4.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
8References
26 Jun 2026Last modified by NVD

Description

Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-1259 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-1273Spring Data Commons property binder allows remote code executionSpring Data Commons fails to properly neutralize special elements in request parameters, allowing crafted input to be bound to object properties. Thi…KEVEPSS 97%analysed9.8CVE-2017-8046Spring Data REST PATCH requests allow remote Java code executionSpring Data REST before 2.6.9 (Ingalls SR9) and before 3.0.1 (Kay SR1), and Spring Boot before 1.5.9 and 2.0 M6, fail to properly validate specially …EPSS 75%analysed8.1CVE-2026-41729Vmware spring data rest expression language injection vulnerabilitySpring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) req…EPSS 0.40%7.5CVE-2026-41728Vmware spring data rest improper access control vulnerabilitySpring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when …EPSS 0.35%7.5CVE-2026-41716Broadcom spring data commons allocation without limits vulnerabilitySpring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing heap exhaustion throug…EPSS 0.46%7.5CVE-2026-41695Broadcom spring data commons uncontrolled resource consumption vulnerabilitySpring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property path strings ar…EPSS 0.46%7.5CVE-2018-1274Broadcom spring data commons allocation without limits vulnerabilitySpring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by u…EPSS 1.9%7.1CVE-2026-47849Vmware spring data rest mass assignment vulnerabilitySpring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+j…EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2018-1259), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.