{"id":"CVE-2019-5312","aliases":["GHSA-h755-h99p-9ffv"],"url":"https://o3.security/vulnerability/CVE-2019-5312","summary":"XML External Entity Reference in weixin-java-tools","details":"An issue was discovered in weixin-java-tools v3.3.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file. NOTE: this issue exists because of an incomplete fix for CVE-2018-20318.","published":"2019-01-04T16:29:00.307Z","modified":"2026-08-27T08:15:29.234495Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"com.github.binarywang:weixin-java-common","fixedVersion":"3.3.2.B"}],"fix":{"url":"https://github.com/Wechat-Group/WxJava/commit/8ec61d1328f50e23cd14285a950ca57a088b32b2","label":"Wechat-Group/WxJava@8ec61d1"},"references":[{"type":"FIX","url":"https://github.com/Wechat-Group/WxJava/issues/903"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-5312"},{"type":"WEB","url":"https://github.com/Wechat-Group/WxJava/issues/903#issuecomment-453747039"},{"type":"WEB","url":"https://github.com/Wechat-Group/WxJava/commit/8ec61d1328f50e23cd14285a950ca57a088b32b2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T08:15:29.234495Z"}}