AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-12400

MEDIUM · CVSS 5.5 EPSS 0.78%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-08-23 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-12400
Severity
MEDIUM
CVSS
5.5
EPSS
0.78%
Apache Java

Original NVD Description

In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this implementation might be cached and re-used by Apache Santuario - XML Security for Java, leading to potential security flaws when validating signed documents, etc. The vulnerability affects Apache Santuario - XML Security for Java 2.0.x releases from 2.0.3 and all 2.1.x releases before 2.1.4.