CVE-2017-12627: Apache Xerces-C++

Critical severity, CVSS 9.8. EPSS: 8.1% chance of exploitation in the next 30 days.

In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.

Affected products

  • Apache Xerces-C++: before 3.2.1 (fixed in 3.2.1)

Published 2018-03-01. Last modified 2026-06-17.