It was discovered that the XML::Atom Perl module before version 0.39 did not disable external entities when parsing XML from potentially untrusted sources. This may allow attackers to gain read access to otherwise protected resources, depending on how the library is used.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NXml\ \
APPXml\atom_project
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2026-9390CRITICAL9.1PL ✓same product
XPath injection w XML::Sig dla Perl — obejście weryfikacji podpisu XML
CVE-2026-9487CRITICAL9.1PL ✓same product
XML::Sig dla Perl – signature wrapping przez zduplikowane ID
CVE-2025-40934CRITICAL9.3PL ✓same product
XML-Sig dla Perl: pominięcie podpisu skutkuje błędną walidacją
CVE-2026-18568HIGH7.5PL ✓same product
XML::Sig dla Perl — pominięcie weryfikacji podpisu XML (signature bypass)