CVE-2026-22186 ("XML External Identity (XXE) vulnerability during metadata parsing")

Affects Bio-Formats <= 8.4.0

back to Advisories

Synopsis

Bio-Formats up to 8.4.0 contains an XML External Entity (XXE) vulnerability.

Background

Bio-Formats up to 8.4.0 contains an XML External Entity (XXE) vulnerability. The issue is caused by an insecurely configured DocumentBuilderFactory that allows external entity resolution and external DTD loading when parsing user-supplied XML metadata.

Affected Packages

Bio-Formats <= 8.4.0

Impact

Moderate severity.

Workaround

N/A

Resolution

Bio-Formats should be upgraded to at least 8.5.0.

Thanks

Beatriz Fresno Naumova for notifying the OME team of this security issue via security@openmicroscopy.org.


back to top