CVE-2022-26662
HIGH7.5EPSS 5.6%XML Entity Expansion in trytond and proteus
Published: 3/11/2022Modified: 4/28/2026
Description
An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An unauthenticated user can send a crafted XML-RPC message to consume all the resources of the server.
Affected packages (5)
- Debian/tryton-proteusfrom 0, < 5.0.8-1+deb11u1
- Debian/tryton-serverfrom 0, < 5.0.33-2+deb11u1
- PyPI/proteus>= 5.0.0, < 5.0.12
- PyPI/tryton>= 5.0.0, < 5.0.12, >= 6.0.0, < 6.0.5, >= 6.2.0, < 6.2.2, < 6.2.6, < 6.0.16, < 5.0.46
- PyPI/trytond>= 5.0.0, < 5.0.46
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
References (9)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2022-26662
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2022-26662
- PATCHhttps://hg.tryton.org/trytond
- WEBhttps://bugs.tryton.org/issue11244
- WEBhttps://discuss.tryton.org/t/security-release-for-issue11219-and-issue11244/5059
- WEBhttps://lists.debian.org/debian-lts-announce/2022/03/msg00016.html
- WEBhttps://lists.debian.org/debian-lts-announce/2022/03/msg00017.html
- WEBhttps://www.debian.org/security/2022/dsa-5098
- WEBhttps://www.debian.org/security/2022/dsa-5099