CVE-2026-47079 (GCVE-0-2026-47079)
Vulnerability from cvelistv5
Published
2026-08-21 09:52
Modified
2026-08-21 12:19
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-838 - Inappropriate Encoding for Output Context
Summary
Inappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, Cross-site Scripting.
This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape_string/1, XmlBuilder.escape_entity/1.
XmlBuilder.generate/1 does not escape literal & characters in text or attribute values when they are followed by an entity-like token (lt;, gt;, amp;, quot;, apos;). As a result, attacker-supplied input such as <script> is emitted verbatim into the serialized XML rather than being escaped to &lt;script&gt;. When a downstream XML parser later reads the document, it decodes the entity sequences into the literal characters <script>, promoting inert-looking text into real markup. This allows an attacker to bypass upstream filters that block raw < and > characters, injecting markup into any downstream consumer that parses the produced XML and renders the text content in a markup-sensitive context (HTML, SVG, RSS/Atom feeds). Both element text and attribute values are affected.
This issue affects xml_builder: from 0.0.6 before 2.4.1.
References
Impacted products
| Vendor | Product | Version | |||||||
|---|---|---|---|---|---|---|---|---|---|
| joshnuss | xml_builder |
Version: 0.0.6 ≤ cpe:2.3:a:joshnuss:xml_builder:*:*:*:*:*:*:*:* |
|||||||
|
|||||||||
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-47079",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-21T12:17:52.012230Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T12:19:47.179Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/joshnuss/xml_builder/security/advisories/GHSA-5hjx-8g53-cmvm"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://repo.hex.pm",
"cpes": [
"cpe:2.3:a:joshnuss:xml_builder:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"modules": [
"\u0027Elixir.XmlBuilder\u0027"
],
"packageName": "xml_builder",
"packageURL": "pkg:hex/xml_builder",
"product": "xml_builder",
"programFiles": [
"lib/xml_builder.ex"
],
"programRoutines": [
{
"name": "\u0027Elixir.XmlBuilder\u0027:generate/1"
},
{
"name": "\u0027Elixir.XmlBuilder\u0027:generate/2"
},
{
"name": "\u0027Elixir.XmlBuilder\u0027:escape_string/1"
},
{
"name": "\u0027Elixir.XmlBuilder\u0027:escape_entity/1"
}
],
"repo": "https://github.com/joshnuss/xml_builder",
"vendor": "joshnuss",
"versions": [
{
"lessThan": "2.4.1",
"status": "affected",
"version": "0.0.6",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://github.com",
"cpes": [
"cpe:2.3:a:joshnuss:xml_builder:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"modules": [
"\u0027Elixir.XmlBuilder\u0027"
],
"packageName": "joshnuss/xml_builder",
"packageURL": "pkg:github/joshnuss/xml_builder",
"product": "xml_builder",
"programFiles": [
"lib/xml_builder.ex"
],
"programRoutines": [
{
"name": "\u0027Elixir.XmlBuilder\u0027:generate/1"
},
{
"name": "\u0027Elixir.XmlBuilder\u0027:generate/2"
},
{
"name": "\u0027Elixir.XmlBuilder\u0027:escape_string/1"
},
{
"name": "\u0027Elixir.XmlBuilder\u0027:escape_entity/1"
}
],
"repo": "https://github.com/joshnuss/xml_builder",
"vendor": "joshnuss",
"versions": [
{
"lessThan": "c3390e2046ec297b3bb8c30d5779cdfd6508c275",
"status": "affected",
"version": "aae31e6e8ac837bcbb8afb816c0d14324b5cfe2b",
"versionType": "git"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:joshnuss:xml_builder:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2.4.1",
"versionStartIncluding": "0.0.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Peter Ullrich"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Joshua Nussbaum"
},
{
"lang": "en",
"type": "coordinator",
"value": "Jonatan M\u00e4nnchen / EEF"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eInappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (\u003ccode\u003eXmlBuilder\u003c/code\u003e module) allows Content Spoofing, Cross-site Scripting.\u003c/p\u003e\n\u003cp\u003eThis vulnerability is associated with program files \u003ccode\u003elib/xml_builder.ex\u003c/code\u003e and program routines \u003ccode\u003eXmlBuilder.generate/1\u003c/code\u003e, \u003ccode\u003eXmlBuilder.generate/2\u003c/code\u003e, \u003ccode\u003eXmlBuilder.escape_string/1\u003c/code\u003e, \u003ccode\u003eXmlBuilder.escape_entity/1\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003eXmlBuilder.generate/1\u003c/code\u003e does not escape literal \u003ccode\u003e\u0026amp;\u003c/code\u003e characters in text or attribute values when they are followed by an entity-like token (\u003ccode\u003elt;\u003c/code\u003e, \u003ccode\u003egt;\u003c/code\u003e, \u003ccode\u003eamp;\u003c/code\u003e, \u003ccode\u003equot;\u003c/code\u003e, \u003ccode\u003eapos;\u003c/code\u003e). As a result, attacker-supplied input such as \u003ccode\u003e\u0026amp;lt;script\u0026amp;gt;\u003c/code\u003e is emitted verbatim into the serialized XML rather than being escaped to \u003ccode\u003e\u0026amp;amp;lt;script\u0026amp;amp;gt;\u003c/code\u003e. When a downstream XML parser later reads the document, it decodes the entity sequences into the literal characters \u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e, promoting inert-looking text into real markup. This allows an attacker to bypass upstream filters that block raw \u003ccode\u003e\u0026lt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;\u003c/code\u003e characters, injecting markup into any downstream consumer that parses the produced XML and renders the text content in a markup-sensitive context (HTML, SVG, RSS/Atom feeds). Both element text and attribute values are affected.\u003c/p\u003e\n\u003cp\u003eThis issue affects xml_builder: from 0.0.6 before 2.4.1.\u003c/p\u003e"
},
{
"base64": false,
"type": "text/markdown",
"value": "Inappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (`XmlBuilder` module) allows Content Spoofing, Cross-site Scripting.\n\nThis vulnerability is associated with program files `lib/xml_builder.ex` and program routines `XmlBuilder.generate/1`, `XmlBuilder.generate/2`, `XmlBuilder.escape_string/1`, `XmlBuilder.escape_entity/1`.\n\n`XmlBuilder.generate/1` does not escape literal `\u0026` characters in text or attribute values when they are followed by an entity-like token (`lt;`, `gt;`, `amp;`, `quot;`, `apos;`). As a result, attacker-supplied input such as `\u0026lt;script\u0026gt;` is emitted verbatim into the serialized XML rather than being escaped to `\u0026amp;lt;script\u0026amp;gt;`. When a downstream XML parser later reads the document, it decodes the entity sequences into the literal characters `\u003cscript\u003e`, promoting inert-looking text into real markup. This allows an attacker to bypass upstream filters that block raw `\u003c` and `\u003e` characters, injecting markup into any downstream consumer that parses the produced XML and renders the text content in a markup-sensitive context (HTML, SVG, RSS/Atom feeds). Both element text and attribute values are affected.\n\nThis issue affects xml_builder: from 0.0.6 before 2.4.1."
}
],
"value": "Inappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, Cross-site Scripting.\n\nThis vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape_string/1, XmlBuilder.escape_entity/1.\n\nXmlBuilder.generate/1 does not escape literal \u0026 characters in text or attribute values when they are followed by an entity-like token (lt;, gt;, amp;, quot;, apos;). As a result, attacker-supplied input such as \u0026lt;script\u0026gt; is emitted verbatim into the serialized XML rather than being escaped to \u0026amp;lt;script\u0026amp;gt;. When a downstream XML parser later reads the document, it decodes the entity sequences into the literal characters \u003cscript\u003e, promoting inert-looking text into real markup. This allows an attacker to bypass upstream filters that block raw \u003c and \u003e characters, injecting markup into any downstream consumer that parses the produced XML and renders the text content in a markup-sensitive context (HTML, SVG, RSS/Atom feeds). Both element text and attribute values are affected.\n\nThis issue affects xml_builder: from 0.0.6 before 2.4.1."
}
],
"impacts": [
{
"capecId": "CAPEC-120",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-120 Double Encoding"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "LOCAL",
"baseScore": 2.1,
"baseSeverity": "LOW",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-838",
"description": "CWE-838 Inappropriate Encoding for Output Context",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T09:52:44.178Z",
"orgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"shortName": "EEF"
},
"references": [
{
"tags": [
"vendor-advisory",
"related"
],
"url": "https://github.com/joshnuss/xml_builder/security/advisories/GHSA-5hjx-8g53-cmvm"
},
{
"tags": [
"related"
],
"url": "https://cna.erlef.org/cves/CVE-2026-47079.html"
},
{
"tags": [
"related"
],
"url": "https://osv.dev/vulnerability/EEF-CVE-2026-47079"
},
{
"tags": [
"patch"
],
"url": "https://github.com/joshnuss/xml_builder/commit/c3390e2046ec297b3bb8c30d5779cdfd6508c275"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Round-trip Corruption via Improper Entity Escaping in xml_builder"
}
},
"cveMetadata": {
"assignerOrgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"assignerShortName": "EEF",
"cveId": "CVE-2026-47079",
"datePublished": "2026-08-21T09:52:44.178Z",
"dateReserved": "2026-05-18T17:28:10.319Z",
"dateUpdated": "2026-08-21T12:19:47.179Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"vulnerability-lookup:meta": {
"vulnrichment": {
"containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2026-47079\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"poc\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-08-21T12:17:52.012230Z\"}}}], \"references\": [{\"url\": \"https://github.com/joshnuss/xml_builder/security/advisories/GHSA-5hjx-8g53-cmvm\", \"tags\": [\"exploit\"]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-08-21T12:18:04.561Z\"}}], \"cna\": {\"title\": \"Round-trip Corruption via Improper Entity Escaping in xml_builder\", \"source\": {\"discovery\": \"EXTERNAL\"}, \"credits\": [{\"lang\": \"en\", \"type\": \"finder\", \"value\": \"Peter Ullrich\"}, {\"lang\": \"en\", \"type\": \"remediation developer\", \"value\": \"Joshua Nussbaum\"}, {\"lang\": \"en\", \"type\": \"coordinator\", \"value\": \"Jonatan M\\u00e4nnchen / EEF\"}], \"impacts\": [{\"capecId\": \"CAPEC-120\", \"descriptions\": [{\"lang\": \"en\", \"value\": \"CAPEC-120 Double Encoding\"}]}], \"metrics\": [{\"format\": \"CVSS\", \"cvssV4_0\": {\"Safety\": \"NOT_DEFINED\", \"version\": \"4.0\", \"Recovery\": \"NOT_DEFINED\", \"baseScore\": 2.1, \"Automatable\": \"NOT_DEFINED\", \"attackVector\": \"LOCAL\", \"baseSeverity\": \"LOW\", \"valueDensity\": \"NOT_DEFINED\", \"vectorString\": \"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N\", \"providerUrgency\": \"NOT_DEFINED\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"attackRequirements\": \"PRESENT\", \"privilegesRequired\": \"NONE\", \"subIntegrityImpact\": \"LOW\", \"vulnIntegrityImpact\": \"NONE\", \"subAvailabilityImpact\": \"NONE\", \"vulnAvailabilityImpact\": \"NONE\", \"subConfidentialityImpact\": \"NONE\", \"vulnConfidentialityImpact\": \"NONE\", \"vulnerabilityResponseEffort\": \"NOT_DEFINED\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"GENERAL\"}]}], \"affected\": [{\"cpes\": [\"cpe:2.3:a:joshnuss:xml_builder:*:*:*:*:*:*:*:*\"], \"repo\": \"https://github.com/joshnuss/xml_builder\", \"vendor\": \"joshnuss\", \"modules\": [\"\u0027Elixir.XmlBuilder\u0027\"], \"product\": \"xml_builder\", \"versions\": [{\"status\": \"affected\", \"version\": \"0.0.6\", \"lessThan\": \"2.4.1\", \"versionType\": \"semver\"}], \"packageURL\": \"pkg:hex/xml_builder\", \"packageName\": \"xml_builder\", \"programFiles\": [\"lib/xml_builder.ex\"], \"collectionURL\": \"https://repo.hex.pm\", \"defaultStatus\": \"unaffected\", \"programRoutines\": [{\"name\": \"\u0027Elixir.XmlBuilder\u0027:generate/1\"}, {\"name\": \"\u0027Elixir.XmlBuilder\u0027:generate/2\"}, {\"name\": \"\u0027Elixir.XmlBuilder\u0027:escape_string/1\"}, {\"name\": \"\u0027Elixir.XmlBuilder\u0027:escape_entity/1\"}]}, {\"cpes\": [\"cpe:2.3:a:joshnuss:xml_builder:*:*:*:*:*:*:*:*\"], \"repo\": \"https://github.com/joshnuss/xml_builder\", \"vendor\": \"joshnuss\", \"modules\": [\"\u0027Elixir.XmlBuilder\u0027\"], \"product\": \"xml_builder\", \"versions\": [{\"status\": \"affected\", \"version\": \"aae31e6e8ac837bcbb8afb816c0d14324b5cfe2b\", \"lessThan\": \"c3390e2046ec297b3bb8c30d5779cdfd6508c275\", \"versionType\": \"git\"}], \"packageURL\": \"pkg:github/joshnuss/xml_builder\", \"packageName\": \"joshnuss/xml_builder\", \"programFiles\": [\"lib/xml_builder.ex\"], \"collectionURL\": \"https://github.com\", \"defaultStatus\": \"unaffected\", \"programRoutines\": [{\"name\": \"\u0027Elixir.XmlBuilder\u0027:generate/1\"}, {\"name\": \"\u0027Elixir.XmlBuilder\u0027:generate/2\"}, {\"name\": \"\u0027Elixir.XmlBuilder\u0027:escape_string/1\"}, {\"name\": \"\u0027Elixir.XmlBuilder\u0027:escape_entity/1\"}]}], \"references\": [{\"url\": \"https://github.com/joshnuss/xml_builder/security/advisories/GHSA-5hjx-8g53-cmvm\", \"tags\": [\"vendor-advisory\", \"related\"]}, {\"url\": \"https://cna.erlef.org/cves/CVE-2026-47079.html\", \"tags\": [\"related\"]}, {\"url\": \"https://osv.dev/vulnerability/EEF-CVE-2026-47079\", \"tags\": [\"related\"]}, {\"url\": \"https://github.com/joshnuss/xml_builder/commit/c3390e2046ec297b3bb8c30d5779cdfd6508c275\", \"tags\": [\"patch\"]}], \"descriptions\": [{\"lang\": \"en\", \"value\": \"Inappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, Cross-site Scripting.\\n\\nThis vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape_string/1, XmlBuilder.escape_entity/1.\\n\\nXmlBuilder.generate/1 does not escape literal \u0026 characters in text or attribute values when they are followed by an entity-like token (lt;, gt;, amp;, quot;, apos;). As a result, attacker-supplied input such as \u0026lt;script\u0026gt; is emitted verbatim into the serialized XML rather than being escaped to \u0026amp;lt;script\u0026amp;gt;. When a downstream XML parser later reads the document, it decodes the entity sequences into the literal characters \u003cscript\u003e, promoting inert-looking text into real markup. This allows an attacker to bypass upstream filters that block raw \u003c and \u003e characters, injecting markup into any downstream consumer that parses the produced XML and renders the text content in a markup-sensitive context (HTML, SVG, RSS/Atom feeds). Both element text and attribute values are affected.\\n\\nThis issue affects xml_builder: from 0.0.6 before 2.4.1.\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"\u003cp\u003eInappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (\u003ccode\u003eXmlBuilder\u003c/code\u003e module) allows Content Spoofing, Cross-site Scripting.\u003c/p\u003e\\n\u003cp\u003eThis vulnerability is associated with program files \u003ccode\u003elib/xml_builder.ex\u003c/code\u003e and program routines \u003ccode\u003eXmlBuilder.generate/1\u003c/code\u003e, \u003ccode\u003eXmlBuilder.generate/2\u003c/code\u003e, \u003ccode\u003eXmlBuilder.escape_string/1\u003c/code\u003e, \u003ccode\u003eXmlBuilder.escape_entity/1\u003c/code\u003e.\u003c/p\u003e\\n\u003cp\u003e\u003ccode\u003eXmlBuilder.generate/1\u003c/code\u003e does not escape literal \u003ccode\u003e\u0026amp;\u003c/code\u003e characters in text or attribute values when they are followed by an entity-like token (\u003ccode\u003elt;\u003c/code\u003e, \u003ccode\u003egt;\u003c/code\u003e, \u003ccode\u003eamp;\u003c/code\u003e, \u003ccode\u003equot;\u003c/code\u003e, \u003ccode\u003eapos;\u003c/code\u003e). As a result, attacker-supplied input such as \u003ccode\u003e\u0026amp;lt;script\u0026amp;gt;\u003c/code\u003e is emitted verbatim into the serialized XML rather than being escaped to \u003ccode\u003e\u0026amp;amp;lt;script\u0026amp;amp;gt;\u003c/code\u003e. When a downstream XML parser later reads the document, it decodes the entity sequences into the literal characters \u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e, promoting inert-looking text into real markup. This allows an attacker to bypass upstream filters that block raw \u003ccode\u003e\u0026lt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;\u003c/code\u003e characters, injecting markup into any downstream consumer that parses the produced XML and renders the text content in a markup-sensitive context (HTML, SVG, RSS/Atom feeds). Both element text and attribute values are affected.\u003c/p\u003e\\n\u003cp\u003eThis issue affects xml_builder: from 0.0.6 before 2.4.1.\u003c/p\u003e\", \"base64\": false}, {\"type\": \"text/markdown\", \"value\": \"Inappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (`XmlBuilder` module) allows Content Spoofing, Cross-site Scripting.\\n\\nThis vulnerability is associated with program files `lib/xml_builder.ex` and program routines `XmlBuilder.generate/1`, `XmlBuilder.generate/2`, `XmlBuilder.escape_string/1`, `XmlBuilder.escape_entity/1`.\\n\\n`XmlBuilder.generate/1` does not escape literal `\u0026` characters in text or attribute values when they are followed by an entity-like token (`lt;`, `gt;`, `amp;`, `quot;`, `apos;`). As a result, attacker-supplied input such as `\u0026lt;script\u0026gt;` is emitted verbatim into the serialized XML rather than being escaped to `\u0026amp;lt;script\u0026amp;gt;`. When a downstream XML parser later reads the document, it decodes the entity sequences into the literal characters `\u003cscript\u003e`, promoting inert-looking text into real markup. This allows an attacker to bypass upstream filters that block raw `\u003c` and `\u003e` characters, injecting markup into any downstream consumer that parses the produced XML and renders the text content in a markup-sensitive context (HTML, SVG, RSS/Atom feeds). Both element text and attribute values are affected.\\n\\nThis issue affects xml_builder: from 0.0.6 before 2.4.1.\", \"base64\": false}]}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-838\", \"description\": \"CWE-838 Inappropriate Encoding for Output Context\"}]}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:a:joshnuss:xml_builder:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"2.4.1\", \"versionStartIncluding\": \"0.0.6\"}], \"operator\": \"OR\"}], \"operator\": \"AND\"}], \"providerMetadata\": {\"orgId\": \"6b3ad84c-e1a6-4bf7-a703-f496b71e49db\", \"shortName\": \"EEF\", \"dateUpdated\": \"2026-08-21T09:52:44.178Z\"}}}",
"cveMetadata": "{\"cveId\": \"CVE-2026-47079\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-21T12:19:47.179Z\", \"dateReserved\": \"2026-05-18T17:28:10.319Z\", \"assignerOrgId\": \"6b3ad84c-e1a6-4bf7-a703-f496b71e49db\", \"datePublished\": \"2026-08-21T09:52:44.178Z\", \"assignerShortName\": \"EEF\"}",
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
}
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…