🔐 CVE Alert

CVE-2026-19614

UNKNOWN 0.0

XML External Entity (XXE) Injection in CyberELF NanoXML

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3.

CWE CWE-611
Vendor cyberelf
Product nanoxml
Published Sep 8, 2026
Last Updated Sep 8, 2026
Stay Ahead of the Next One

Get instant alerts for cyberelf nanoxml

Be the first to know when new unknown vulnerabilities affecting cyberelf nanoxml are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

CyberELF / NanoXML
2.2.3

References

NVD ↗ CVE.org ↗ EPSS Data ↗
thalesgroup.com: https://www.thalesgroup.com/en/search/cybersecurity/cybersecurity-services/cve-2026-19614

Credits

Dominique RIGHETTO