Critical XML Entity Vulnerabilities Fixed in Fedora 43 and 44 Updates

Critical XML Entity Vulnerabilities Fixed in Fedora 43 and 44 Updates

First seen 11 Jun 2026, 03:25 UTC Linuxsecurity 94% similarity 60.6

Article Content

Browse articles
ThreatCluster

On June 11, 2026, Fedora released updates for XMLStarlet in versions 43 and 44 to address XML External Entity (XXE) vulnerabilities. These vulnerabilities could allow attackers to exploit XML parsing features, potentially leading to unauthorized access to sensitive data. The updates were made available by Vitezslav Crhonek and are crucial for users of Fedora 43 and 44. Users are advised to upgrade using the 'dnf' update program. The vulnerabilities were identified in version 1.6.1-30 of XMLStarlet, which is a command-line toolkit for XML processing. The updates are essential for maintaining security and preventing potential exploitation. No specific CVEs were mentioned in the articles, but the nature of the vulnerabilities suggests a significant risk if left unpatched.

Key Points: • Fedora 43 and 44 released critical updates for XMLStarlet on June 11, 2026. • The updates fix XML External Entity (XXE) vulnerabilities that could expose sensitive data. • Users are urged to apply the updates immediately using the 'dnf' update program.

ThreatCluster AI

Timeline

2026-05-27
XXE vulnerabilities identified
Vitezslav Crhonek identified XXE vulnerabilities in XMLStarlet that required urgent attention.
Linuxsecurity
2026-06-11
Fedora 43 XMLStarlet update released
An update was issued to fix XXE vulnerabilities in XMLStarlet version 1.6.1-30 for Fedora 43.
Linuxsecurity
2026-06-11
Fedora 44 XMLStarlet update released
An update was issued to fix XXE vulnerabilities in XMLStarlet version 1.6.1-30 for Fedora 44.
Linuxsecurity

Community

Browse all →