← Vulnerability feed

Vulnerability record · CVE-2020-11991 · published 11 September 2020

CVE-2020-11991: Apache Cocoon StreamGenerator XML external entity file disclosure

Apache · Cocoon

Apache Cocoon's StreamGenerator parses user-supplied XML without disabling external system entities, allowing XML External Entity (XXE) injection. An attacker can craft XML that references local files, causing the server to read and return their contents. This exposes sensitive files such as configuration or credential files on the host.

7.5 CVSS 3.1 High EPSS 72% · top 0.6% CWE-611 · XML external entity (XXE)
7.5CVSS 3.1 base score, v2 5.0
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityHigh CVSS (7.5) with no authentication or interaction required, public exploit references and a very high EPSS score, though no confirmed in-the-wild KEV listing.

What it is

Apache Cocoon's StreamGenerator parses user-supplied XML without disabling external system entities, allowing XML External Entity (XXE) injection. An attacker can craft XML that references local files, causing the server to read and return their contents. This exposes sensitive files such as configuration or credential files on the host.

Impact

An attacker gains read access to arbitrary files on the server filesystem, potentially leaking credentials, configuration and other sensitive data. There is no write or code execution impact per the CVSS vector.

Attack surface

Reachable over the network via the StreamGenerator component that accepts user-provided XML; the CVSS vector shows no privileges or user interaction required. Any endpoint feeding attacker-controlled XML into StreamGenerator is exposed.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.72456, 99.4th percentile) and both references are tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade Apache Cocoon to a version that fixes the StreamGenerator XXE issue; check the vendor advisory for the fixed release.
  • If patching is not immediate, disable or restrict the StreamGenerator component and reject untrusted XML input.
  • Configure the XML parser to disable external entity and DTD processing (e.g., disallow-doctype-decl, external-general-entities and external-parameter-entities off).
  • Run the service with least privilege and restrict filesystem read access so leaked files are limited.
  • Place the service behind a WAF or input filter that blocks DOCTYPE and external entity declarations in XML payloads.

Detection

  • Search application and access logs for XML requests containing DOCTYPE, ENTITY or SYSTEM keywords.
  • Monitor for outbound or local file reads triggered by XML parsing, especially requests to unusual file paths.
  • Alert on StreamGenerator endpoint requests with XML bodies from untrusted sources.
  • Review server file access logs for reads of sensitive files (e.g., /etc/passwd, config files) correlated with web requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-11991 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-49733Apache cocoon xml external entity (xxe) vulnerabilityImproper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users…EPSS 1.3%9.8CVE-2022-45135Apache cocoon sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This issue affects Apache Cocoon:…EPSS 1.1%7.5CVE-2025-24783Apache cocoon vulnerability** UNSUPPORTED WHEN ASSIGNED ** Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Apache Cocoon. This issue affects …EPSS 0.79%5.0CVE-2003-1172Apache cocoon vulnerabilityDirectory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access a…EPSS 31%9.8CVE-2025-58360GeoServer WMS GetMap XXE allows unauthenticated file read and SSRFGeoServer versions 2.26.0 through 2.26.2 and before 2.25.6 accept XML input at the /geoserver/wms GetMap endpoint without sufficiently restricting ex…KEVEPSS 61%analysed9.8CVE-2025-2776SysAid On-Prem unauthenticated XXE in Server URL processingSysAid On-Prem versions up to 23.3.40 process the Server URL without restricting XML external entities, so an unauthenticated attacker can supply cra…KEVEPSS 64%analysed7.5CVE-2025-2775SysAid On-Prem unauthenticated XXE in Checkin processingSysAid On-Prem versions up to 23.3.40 process Checkin XML without restricting external entities, so an unauthenticated attacker can supply a crafted …KEVEPSS 43%analysed7.5CVE-2023-45727Proself XXE flaw allows unauthenticated file readProself Enterprise/Standard, Gateway, and Mail Sanitize editions fail to restrict XML external entities when parsing malformed XML requests. A remote…KEVEPSS 3.5%analysed

Source: NIST National Vulnerability Database (record CVE-2020-11991), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.