Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2026-88789 — 针对 CVE-2026-88789 的可运行概念验证复现程序,演示 Apache Camel Quarkus camel-quarkus-support-xalan 中通过 XSLT TransformerFactory 触发的 XXE 和 SSRF。 | Kitploit
工具/GitHubGitHub/oscerd/cve-2026-88789
防御工具漏洞分析漏洞利用Web安全学习与教育
GitHuboscerd/cve-2026-88789

CVE-2026-88789

针对 CVE-2026-88789 的可运行概念验证复现程序,演示 Apache Camel Quarkus camel-quarkus-support-xalan 中通过 XSLT TransformerFactory 触发的 XXE 和 SSRF。

查看仓库
16小时16分前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2026-88789 — Camel Quarkus:强制使用 Xalan TransformerFactory 导致 JAXP 外部访问限制失效

针对 Apache Camel Quarkus 漏洞的可运行概念验证复现程序。在该漏洞中,XSLT 支持扩展(camel-quarkus-support-xalan)向 xslt 组件提供其自有的、由 Xalan 支持的 TransformerFactory,并将其注册为 JAXP 默认实现。Xalan-J 2.7.x 早于 JAXP 1.5,无法遵循 javax.xml.XMLConstants.ACCESS_EXTERNAL_DTD 或 ACCESS_EXTERNAL_STYLESHEET —— 对这两者调用 setAttribute() 都会抛出 IllegalArgumentException —— 因此 Apache Camel 对其创建的 TransformerFactory 所施加的外部访问限制从未生效。

运行时目录技术栈
Camel Quarkuscamel-quarkus/Camel Quarkus 3.36.0(Quarkus 3.36.0,Camel 4.20.0)

仅限 Camel Quarkus。 存在漏洞的代码是 Camel Quarkus 扩展,而非 Camel 组件。普通 Camel 和 Camel Spring Boot 使用 JDK 的 TransformerFactory,它遵循这两个属性,因此那里没有 可复现的内容 —— 本仓库因此没有 camel-spring-boot/ 变体。

它演示了什么

提供被转换 XML 文档的攻击者,可以通过该文档中的外部实体声明读取本地文件或访问内部网络位置。

cd camel-quarkus
mvn clean package
docker compose up -d --build
curl -s http://localhost:8080/exploit/attack
docker compose down

在受影响的构建上的预期输出(节选 —— 驱动程序运行六个探测,参见 camel-quarkus/README.md):

1) xslt endpoint, body is a StreamSource, external entity -> file:///tmp/cve-2026-88789-secrets/db-password.txt
     transformation result: [db.password=LOCAL-FILE-s3cr3t-99]
     local file contents in the output: true

2) xslt endpoint, body is a StreamSource, external entity -> http://127.0.0.1:8080/internal/secret
     transformation result: [INTERNAL-SECRET-s3cr3t-42]
     internal endpoint response in the output: true

4) CONTROL - same document as a String body (Camel converts it to a SAXSource itself)
     transformation result: []
     local file contents in the output: false

5) TransformerFactory.newInstance() anywhere in the application
     factory: org.apache.camel.quarkus.support.xalan.XalanTransformerFactory
     setAttribute(ACCESS_EXTERNAL_DTD, ""):        REFUSED, IllegalArgumentException: ...
     identity transform of the same document: [... <data>db.password=LOCAL-FILE-s3cr3t-99</data> ...]

Requests the XML parser made to internal endpoints on its own: [GET /internal/secret, GET /internal/leak.dtd]

>>> PROVEN: ...

也已针对 Camel Quarkus 3.40.0 验证:每个泄漏探测都归于沉寂,内部端点完全收不到请求,驱动程序打印 NOT reproduced。

哪些路径受影响

在 xslt 组件路径上,只有已经以 javax.xml.transform.Source 形式到达转换器的消息体受影响。其他类型的消息体 —— String、byte[]、InputStream —— 会被 Apache Camel 转换为禁用了外部实体和外部 DTD 加载的 SAXSource,因此不受影响。复现程序中的探测 4 就是那条安全路径,与不安全路径并排展示。

由于该工厂还被注册为 JAXP 默认实现(该支持扩展附带 META-INF/services/javax.xml.transform.TransformerFactory),应用程序中任何其他通过 TransformerFactory.newInstance() 获取工厂的代码都会在无错误提示的情况下失去同样的限制。这就是为什么公告列出了那些自身从不进行任何转换的扩展:

扩展暴露面
camel-quarkus-xsltxslt 组件路径以及 JAXP 默认实现
camel-quarkus-xslt-saxonJAXP 默认实现
camel-quarkus-tikaJAXP 默认实现
camel-quarkus-xmlsecurityJAXP 默认实现

漏洞摘要

属性值
组件camel-quarkus-support-xalan(XSLT 支持扩展)
CWECWE-611(XML 外部实体引用限制不当)
严重性高
攻击向量在被转换的 XML 文档中声明外部实体或外部 DTD,且消息体已以 javax.xml.transform.Source 形式到达 xslt 端点
影响读取本地文件;向内部网络位置发起请求(SSRF)
受影响版本从 3.2.0 起至 3.33.3 之前,从 3.34.0 起至 3.40.0 之前
修复版本3.33.3(LTS 分支)、3.40.0
GitHub issueapache/camel-quarkus#9115
致谢由内部使用 Claude Security Tool 分析发现

公告:https://camel.apache.org/security/CVE-2026-88789.html

修复方案

XalanTransformerFactory 现在自行施加限制,而不再依赖 Xalan 无法遵循的属性:

  • 被转换的文档使用一个既不解析外部通用实体也不解析外部参数实体、且不加载外部 DTD 的 XMLReader 进行解析 —— 这与 Apache Camel 的 XmlConverter.createSAXParserFactory() 用于 camel-xslt 自行转换为 SAXSource 的消息体时所用的配置相同。携带调用方配置的 XMLReader 的 SAXSource 按原样使用,而 DOMSource 和 StAXSource 已经完成解析。
  • 转换时由 document() 函数获取的资源会被拒绝,除非应用程序自身的 URIResolver 能解析它们;该限制被安装到每一个提供转换对象的入口点上,包括那些 Xalan 不会将工厂解析器复制到其转换器上的 SAX 推送入口点。设置了自己解析器的应用程序 —— camel-xslt 在每次交换时都会这样做 —— 仍像以前一样覆盖它。

已在 main 分支上修复,提交为 9a570b64 和 9dd11779, 并回溯移植到 3.33.x,提交为 ad9c5236 和 3d886769。

如果暂时无法升级

  • 不要将由不可信输入构建的 javax.xml.transform.Source 传入 xslt 端点。将消息体保留为 String、byte[] 或 InputStream,以便 Apache Camel 先将其转换为禁用了外部实体的 SAXSource。
  • 对现有的 Source 消息体使用 convertBodyTo 不是变通方案:该转换会通过同一个工厂执行恒等转换。复现程序中的探测 5 就是那个恒等转换,它会泄漏。
  • 依赖 JAXP 外部访问限制的应用程序或库代码,应显式请求 JDK 实现,即指定 com.sun.org.apache.xalan.internal.xsltc.trax.TransformerFactoryImpl,而不是依赖 TransformerFactory.newInstance()。探测 6 就是那个对照,它会拒绝读取。

免责声明

本仓库出于教育和防御目的发布:帮助 Apache Camel Quarkus 用户理解该漏洞、验证自己是否受影响,并确认升级可以解决该问题。请勿将本材料用于您不拥有或运营的系统。

下载工具