CVE-2026-6501 Details
Description
Improper restriction of XML external entity reference vulnerability in ILM Informatique jOpenDocument allows Data Serialization External Entities Blowup. This issue affects jOpenDocument: 1.5.
A vulnerability exists in ILM Informatique jOpenDocument version 1.5, due to improper restriction of XML external entity references. This flaw allows for a 'Data Serialization External Entities Blowup', where external entities can be exploited to manipulate data serialization processes, potentially leading to denial-of-service conditions or other unintended consequences.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 4, 2026CISA-ADP
Assessed May 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.jopendocument.org/documentation.html | TCS-CERT | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | TCS-CERT |
Affected Products
| Product | Versions |
|---|---|
| ILM Informatique jOpenDocument | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TCS-CERT |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 4, 2026 | New CVE Received | TCS-CERT |
Volerion