CVE-2026-12992: Red Hat Build Of Apicurio Registry
High severity, CVSS 7.4. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. When the VALIDITY rule is set to FULL, an attacker with Developer-role access can upload a WSDL document containing attacker-controlled import locations, causing the registry to issue HTTP requests to arbitrary internal URLs (server-side request forgery).
Affected products
- Red Hat Build Of Apicurio Registry: from 3.0, up to and including 3.2
Published 2026-06-25. Last modified 2026-08-26.