CVE-2014-8152: Apache Santuario XML Security For Java

Medium severity, CVSS 5.0. EPSS: 5.6% chance of exploitation in the next 30 days.

Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a crafted XML document.

Affected products

  • Apache Santuario XML Security For Java: version 2.0.0 only; version 2.0.1 only; version 2.0.2 only

Published 2015-01-21. Last modified 2026-06-17.