Loading HuntDB...

GHSA-h9fv-pf3w-2rh8

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced external entities allowing the injection of arbitrary definitions which is able to access local files and expose their contents via HTTP requests.

Related CVEs

Key Information

GHSA ID
GHSA-h9fv-pf3w-2rh8
Published
August 17, 2022 12:00 AM
Last Modified
August 19, 2022 12:00 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: November 25, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.