CVE-2026-51080 Details
Description
libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.
A XML External Entity (XXE) vulnerability has been identified in libpvestorage-perl version 9.1.1 and libpve-storage-perl version 8.3.7. This vulnerability allows for the inclusion of external entities in XML processing, which could be exploited to access local files or perform server-side request forgery.
Users can upgrade to libpve-storage-perl version 9.1.2 (for Proxmox VE 9.x) or version 8.3.8 (for Proxmox VE 8.x) to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/post-849970 | [email protected] | Issue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| proxmox libpve-storage-perl | 8.3.7 9.1.1 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | Initial Analysis | [email protected] |
| Jul 17, 2026 | CVE Modified | CISA-ADP |
| Jul 17, 2026 | New CVE Received | [email protected] |