CVE-2018-1311: Apache Xerces-C++

High severity, CVSS 8.1. EPSS: 9.5% chance of exploitation in the next 30 days.

The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.

Affected products

  • Apache Xerces-C++: from 3.0.0, before 3.2.5 (fixed in 3.2.5)
  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Fedoraproject Fedora: version 38 only; version 39 only
  • Oracle Goldengate: before 21.4.0.0.0 (fixed in 21.4.0.0.0)
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Eus: version 7.7 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.7 only
  • Red Hat Enterprise Linux Server Tus: version 7.7 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only

Published 2019-12-18. Last modified 2026-06-17.