CVE-2024-8010: WSO2 API Manager

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

The component accepts XML input through the publisher without disabling external entity resolution. This allows malicious actors to submit a crafted XML payload that exploits the unescaped external entity references. By leveraging this vulnerability, a malicious actor can read confidential files from the product's file system or access limited HTTP resources reachable via HTTP GET requests to the vulnerable product.

Affected products

  • WSO2 API Manager: from 3.2.0, before 3.2.0.397 (fixed in 3.2.0.397); from 3.2.1, before 3.2.1.27 (fixed in 3.2.1.27); from 4.0.0, up to and including 4.0.0.310; from 4.1.0, before 4.1.0.171 (fixed in 4.1.0.171); from 4.2.0, before 4.2.0.127 (fixed in 4.2.0.127); from 4.3.0, before 4.3.0.39 (fixed in 4.3.0.39)

Published 2026-04-16. Last modified 2026-06-17.