CVE-2025-64518 | CycloneDX cyclonedx-core-java up to 11.0.0 xml external entity reference (GHSA-6fhj-vr9j-g45r)
A vulnerability marked as problematic has been reported in CycloneDX cyclonedx-core-java up to 11.0.0. The impacted element is an unknown function. The manipulation leads to xml external entity reference.
This vulnerability is documented as CVE-2025-64518. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.