CVE-2020-11991: Apache Cocoon

High severity, CVSS 7.5. EPSS: 72.5% chance of exploitation in the next 30 days.

When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system.

Affected products

  • Apache Cocoon: from 2.1, up to and including 2.1.12

Published 2020-09-11. Last modified 2026-06-17.