XML External Entity (XXE) in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin
UnratedCVE-2026-18061 · Published Sep 11, 2026
Bulletin ID: 2026-109-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 09:30 AM PDT Description: The AWS Advanced JDBC Wrapper is an open-source library that enhances existing JDBC drivers with AWS-specific capabilities such as Aurora failover, IAM authentication, and automated SQL query caching for applications connecting to Amazon Aurora, RDS MySQL, and RDS MariaDB. We identified CVE-2026-18061, an improper restriction of XML external entity (XXE) references in the optional RemoteQueryCachePlugin. When this plugin is enabled with a shared cache, an actor with write access to that cache infrastructure might place crafted XML in a cached column value. When an application subsequently reads that cached result as XML, the wrapper's XML parsers resolve external entities, which might allow the actor to disclose sensitive files readable by the application process, including stored database and IAM role credentials. Impacted versions: >= 3.3.0 and <= 4.2.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Affected versions
Details and references
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 11 | Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration | Unrated | No fix yet |
| Sep 11 | Denial of service in the event stream header decoder in AWS SDK for Go v2 | Unrated | No fix yet |
| Sep 11 | Issue with projen - Path traversal and OS command injection | Unrated | No fix yet |
| Sep 10 | Server-side request forgery in the Session Manager port forwarding functionality in AWS... | Unrated | No fix yet |
| Sep 10 | Integer overflow in tensor buffer validation in Deep Java Library | Unrated | No fix yet |
| Sep 10 | Missing S3 bucket ownership verification in the AWS Security Agent plugin for... | Unrated | No fix yet |