{"id":"CVE-2025-2905","aliases":["GHSA-h94w-8qhg-3xmc"],"url":"https://o3.security/vulnerability/CVE-2025-2905","summary":"WSO2 API Manager XML External Entity (XXE) vulnerability","details":"Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (XXE) resolution in multiple WSO2 Products.\n\nA successful XXE attack could allow a remote, unauthenticated attacker to:\n  *  Read sensitive files from the server’s filesystem.\n  *  Perform denial-of-service (DoS) attacks, which can render the affected service unavailable.","published":"2025-05-05T09:15:15.923Z","modified":"2026-07-09T15:13:28.640456Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.wso2.am:am-distribution-parent","fixedVersion":"2.1.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2025/WSO2-2025-3993/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T15:13:28.640456Z"}}