PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-68280 Apache Software Foundation CVE debrief

CVE-2025-68280 Improper Restriction of XML External Entity Reference vulnerability in Apache SIS allows an attacker to reveal the content of a local file on the server by parsing a specially crafted XML file. This affects Apache SIS versions 0.4 through 1.5. Users should upgrade to version 1.6 or apply a workaround by setting the javax.xml.accessExternalDTD system property.

Vendor
Apache Software Foundation
Product
Apache SIS
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-05
Original CVE updated
2026-09-30
Advisory published
2026-01-05
Advisory updated
2026-09-30

Who should care

Defenders responsible for Apache SIS deployments, particularly those using affected versions (0.4-1.5), should assess exposure and prioritize upgrading to version 1.6 or applying the recommended workaround.

Why it matters

CVE-2025-68280 is a medium-severity vulnerability in Apache SIS that allows an attacker to potentially disclose local file content by parsing a specially crafted XML file. Defenders should prioritize upgrading to version 1.6 or applying a workaround to prevent potential unauthorized disclosure.

  • Potential unauthorized disclosure of local file content
  • Requires verification of affected versions and exposure
  • Necessitates upgrading to version 1.6 or applying a workaround
  • May require review of SIS services and configurations

Technical summary

The vulnerability allows an attacker to reveal the content of a local file on the server running Apache SIS by parsing a specially crafted XML file. This affects SIS services such as reading GeoTIFF files having the GEO_METADATA tag defined by the Defense Geospatial Information Working Group (DGIWG), parsing of ISO 19115 metadata in XML format, parsing of Coordinate Reference Systems defined in the GML format, and parsing of files in GPS Exchange Format (GPX). The issue affects Apache SIS from versions 0.4 through 1.5 inclusive. Users are recommended to upgrade to version 1.6, which will fix the issue.

Defensive priority

Medium priority for upgrading to version 1.6 or applying the recommended workaround

Recommended defensive actions

  • Upgrade to Apache SIS version 1.6
  • Apply a workaround by setting the javax.xml.accessExternalDTD system property
  • Review and update affected SIS services
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, affected versions, and recommended actions. The vulnerability allows an attacker to reveal the content of a local file on the server running Apache SIS by parsing a specially crafted XML file. Evidence is limited to public CVE details and NVD assessments. Defenders should verify affected Apache SIS deployments, particularly versions 0.4 through 1.5, and assess exposure to potential unauthorized disclosure of local file content.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-68280 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-68280

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-68280 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-68280

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.