CVE-2026-34401

Source
https://cve.org/CVERecord?id=CVE-2026-34401
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34401.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-34401
Aliases
  • GHSA-5j32-486h-42ch
Published
2026-03-31T21:05:50.647Z
Modified
2026-04-10T05:43:23.525296Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
XML Notepad: XML External Entity (XXE) Injection via Unsafe XmlTextReader in XML Diff and Schema Loading
Details

XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prior to version 2.9.0.21, XML Notepad does not disable DTD processing by default which means external entities are resolved automatically. There is a well known attack related to malicious DTD files where an attacker to craft a malicious XML file that loads a DTD that causes XML Notepad to make outbound HTTP/SMB requests, potentially leaking local file contents or capturing the victim's NTLM credentials. This issue has been patched in version 2.9.0.21.

Database specific
{
    "cwe_ids": [
        "CWE-611"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34401.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/microsoft/xmlnotepad

Affected ranges

Type
GIT
Repo
https://github.com/microsoft/xmlnotepad
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.9.0.21"
        }
    ]
}

Affected versions

2.*
2.8.0.25
2.8.0.27
2.8.0.29
2.8.0.30
2.8.0.35
2.8.0.39
2.8.0.41
2.8.0.42
2.8.0.44
2.8.0.45
2.8.0.46
2.8.0.47
2.8.0.48
2.8.0.49
2.8.0.50
2.8.0.51
2.8.0.52
2.8.0.53
2.8.0.54
2.8.0.55
2.8.0.56
2.8.0.58
2.8.0.59
2.8.0.60
2.8.0.61
2.8.0.62
2.8.0.63
2.8.0.64
2.8.0.65
2.9.0.0
2.9.0.1
2.9.0.10
2.9.0.11
2.9.0.12
2.9.0.13
2.9.0.14
2.9.0.15
2.9.0.16
2.9.0.17
2.9.0.18
2.9.0.19
2.9.0.2
2.9.0.20
2.9.0.3
2.9.0.4
2.9.0.5
2.9.0.6
2.9.0.7
2.9.0.8
2.9.0.9
v2.*
v2.7
v2.8.0.27
v2.8.0.50
v2.8.0.51

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34401.json"