Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.wso2.carbon.mediation/org.wso2.carbon.localentry
  4. ›
  5. CVE-2025-10713

CVE-2025-10713: WSO2 Carbon Mediation vulnerable to XML External Entity (XXE) attacks

November 5, 2025 (updated November 6, 2025)

An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses user-supplied XML without applying sufficient restrictions, allowing resolution of external entities.

A successful attack could enable a remote, unauthenticated attacker to read sensitive files from the server’s filesystem or perform denial-of-service (DoS) attacks that render affected services unavailable.

References

  • github.com/advisories/GHSA-fvfq-q238-j7j3
  • github.com/wso2/carbon-mediation
  • github.com/wso2/carbon-mediation/commit/b995b2f1db96a4697791f0202cc8713f15640fd5
  • github.com/wso2/carbon-mediation/pull/1784
  • nvd.nist.gov/vuln/detail/CVE-2025-10713
  • security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-4505

Code Behaviors & Features

Detect and mitigate CVE-2025-10713 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions

Solution

Unfortunately, there is no solution available yet.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-611: Improper Restriction of XML External Entity Reference

Source file

maven/org.wso2.carbon.mediation/org.wso2.carbon.localentry/CVE-2025-10713.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 04 Feb 2026 00:35:18 +0000.