CVE-2023-49733: Apache Cocoon

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.

Affected products

  • Apache Cocoon: from 2.2.0, before 2.3.0 (fixed in 2.3.0)

Published 2023-11-30. Last modified 2026-06-17.