CVE-2018-1000644

NameCVE-2018-1000644
DescriptionEclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can result in the disclosure of confidential data, denial of service, server side request forgery, port scanning. This attack appear to be exploitable via Specially crafted RDF file.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1144952

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rdf4j (PTS)bookworm, trixie3.7.7+ds-1vulnerable
forky, sid3.7.7+ds-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
rdf4jsource(unstable)(unfixed)1144952

Notes

https://github.com/eclipse-rdf4j/rdf4j/issues/1056
Fixed by: https://github.com/eclipse-rdf4j/rdf4j/commit/50f2f51950227a4ec595a2922d81da487aba5135 (2.4.1)
When fixing this issue make sure to make the fix complete and not open CVE-2026-15803
Cf. https://gitlab.eclipse.org/security/cve-assignment/-/work_items/175

Search for package or bug name: Reporting problems