CVE-2024-51135: Powertac-Server

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

An XML External Entity (XXE) vulnerability in the component DocumentBuilderFactory of powertac-server v1.9.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.

Affected products

Published 2024-11-11. Last modified 2026-06-17.