CVE-2019-3774

Executive Summary

CVE‑2019‑3774 is an XML External Entity (XXE) flaw in Spring Batch 3.0.9, 4.0.1, 4.1.0 and older unsupported releases. When the framework parses XML payloads from untrusted sources, it can resolve external entities, enabling attackers to read arbitrary files, perform SSRF, or trigger denial‑of‑service. The vulnerability is exploitable via crafted XML input and can lead to data exposure or remote code execution. No patch is available for unsupported versions; supported releases should be upgraded. The flaw is not listed in the CISA KEV database.


Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2019-01-18T22:29:01.050 - Last Modified: 2026-09-01T18:07:18.263

Original Description: Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

"He who knows himself is enlightened."

— Lao Tzu
Source: NVD