RHSA-2025:22195HighCVSS 7.5

Red Hat Security Advisory: Red Hat build of Quarkus 3.20.4 release and security update

Published
December 1, 2025
Last Modified
July 30, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2025-64518 — cyclonedx-core-java: CycloneDX Core (Java): BOM validation is vulnerable to XML External Entity injection

🎯 Affected products1

  • Red Hat build of Quarkus 3.20.4

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Reject or block XML-formatted BOMs from untrusted sources before handing them to the library (e.g., require BOMs to be JSON or only accept BOMs from trusted origins).

🔗 References (17)