CVE-2018-9849: Pulse Secure Pulse Connect Secure

Medium severity, CVSS 5.5. EPSS: 1% chance of exploitation in the next 30 days.

Pulse Secure Pulse Connect Secure 8.1.x before 8.1R14, 8.2.x before 8.2R11, and 8.3.x before 8.3R5 do not properly process nested XML entities, which allows remote attackers to cause a denial of service (memory consumption and memory errors) via a crafted XML document.

Affected products

  • Pulse Secure Pulse Connect Secure: from 8.1, before 8.1r14 (fixed in 8.1r14); from 8.2, before 8.2r11 (fixed in 8.2r11); from 8.3, before 8.3r5 (fixed in 8.3r5)

Published 2018-05-10. Last modified 2026-06-17.