← Back

Restlet

restlet

Vendor: Restlet • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Restlet
1Restlet
May 13, 2026
Nov 30, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities)...Show more
Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities) are properly considered. This is related to XmlRepresentation, DOMRepresentation, SaxRepresentation, and JacksonRepresentation.Show less
1Restlet
1Restlet
May 13, 2026
Nov 30, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP request. This affects use of the Jax-rs extension.
1Restlet
1Restlet
Apr 29, 2026
Oct 10, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allows remote attackers to execute arbitrary Java code via a serialized object, a dif...Show more
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allows remote attackers to execute arbitrary Java code via a serialized object, a different vulnerability than CVE-2013-4221.Show less
1Restlet
1Restlet
Apr 29, 2026
Oct 10, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources using the Java XMLDecoder, which allows remote attackers to execute arbitrary Java code via...Show more
The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources using the Java XMLDecoder, which allows remote attackers to execute arbitrary Java code via crafted XML.Show less