CVE-2026-19614

The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3.

  • Published Sep 8, 2026
  • CVSS 5.3 medium
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-19614 at the National Vulnerability Database