CVE-2026-23739

Description

A flaw was found in Asterisk. The ast_xml_open() function in xml.c processes XML documents using libxml with unsafe parsing options, enabling entity expansion and XInclude processing. A remote attacker can exploit this by providing specially crafted XML input, leading to XML External Entity (XXE) or XInclude-based local file disclosure. This vulnerability could allow the attacker to expose sensitive files from the host system.

Statement

This vulnerability has a LOW impact on Red Hat products. Asterisk, as distributed in Community Projects (EPEL 8/9, Fedora), is affected by an XML External Entity (XXE) and XInclude processing flaw. If an attacker can provide untrusted XML input to Asterisk, it may lead to local file disclosure.

Mitigation

To mitigate this issue, restrict the ability for untrusted users to provide XML input to the Asterisk service. Configure Asterisk to process XML only from trusted sources, or disable any features that accept external XML input if they are not critical for your environment.

Frequently Asked Questions

Want to get errata notifications? Sign up here.