← Back to browse · API

CVE-2022-34169

Severity
HIGH
CVSS
7.5
EPSS
0.81039
Risk score
58.36
CISA KEV
No
PoC
No
Published
2022-07-19
Modified
2026-05-27
First seen
2026-08-07
Aliases
EUVD-2022-6300, GHSA-9339-86WC-4QGF
Products
Apache Software Foundation:Apache Xalan-J Xalan-J ≤2.7.2
Sources
euvd EUVD-2022-6300

Description

The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.

References