CVE-2022-34169

HIGH

Apache Xalan <2.7.3 - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2022-34169. PoCs published by flowerwind, Disnaming, bor8.

AI-analyzed exploit summary This repository contains a functional exploit PoC for CVE-2022-34169, an integer truncation vulnerability in Apache Xalan-J. The tool automates the generation of payloads tailored to different JDK versions by analyzing bytecode and adjusting XSLT files to trigger the vulnerability.

Description

The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.

Exploits (3)

nomisec WORKING POC 93 stars
by flowerwind · poc
https://github.com/flowerwind/AutoGenerateXalanPayload

This repository contains a functional exploit PoC for CVE-2022-34169, an integer truncation vulnerability in Apache Xalan-J. The tool automates the generation of payloads tailored to different JDK versions by analyzing bytecode and adjusting XSLT files to trigger the vulnerability.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apache Xalan-J (JDK 1.6-1.8)
No auth needed
Prerequisites: Target system with vulnerable JDK version (1.6-1.8) · Ability to deliver crafted XSLT payload
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 2 stars
by Disnaming · poc
https://github.com/Disnaming/CVE-2022-34169

This repository contains a functional exploit for CVE-2022-34169, an integer truncation vulnerability in Apache Xalan-J. The exploit leverages the vulnerability to achieve remote code execution (RCE) by manipulating the constant pool size in a crafted XSLT file.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Apache Xalan-J
No auth needed
Prerequisites: Access to a vulnerable Apache Xalan-J instance
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec SCANNER
by bor8 · poc
https://github.com/bor8/CVE-2022-34169

This repository contains a scanner to check if CVE-2022-34169 is fixed on a machine by attempting to exploit a vulnerability in the Apache BCEL library where the constant pool size limit is not properly enforced. It does not execute arbitrary code but detects the presence of the fix by observing runtime behavior.

Classification
Scanner 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: OpenJDK and Oracle JDK versions prior to 1.8.0_341
No auth needed
Prerequisites: Java Development Kit (JDK) to compile and run the scanner
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (24)

Core 24
Core References
Issue Tracking, Mailing List, Vendor Advisory
https://lists.apache.org/thread/2qvl7r43wb4t8p9dd9om1bnkssk07sn8
Issue Tracking, Mailing List, Vendor Advisory
https://lists.apache.org/thread/12pxy4phsry6c34x2ol4fft6xlho4kyw
Mailing List, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2022/07/19/5
Mailing List, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2022/07/19/6
Mailing List, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2022/07/20/2
Mailing List, Patch, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2022/07/20/3
Third Party Advisory vendor-advisory
https://www.debian.org/security/2022/dsa-5188
Third Party Advisory vendor-advisory
https://www.debian.org/security/2022/dsa-5192
Mailing List, Patch, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2022/10/18/2
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2022/10/msg00024.html
Third Party Advisory vendor-advisory
https://www.debian.org/security/2022/dsa-5256
Mailing List, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2022/11/04/8
Mailing List, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2022/11/07/2

Scores

CVSS v3 7.5
EPSS 0.1095
EPSS Percentile 93.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-681
Status published
Products (36)
apache/xalan-java < 2.7.2
Apache Software Foundation/Apache Xalan-J Xalan-J - 2.7.2
azul/zulu 6.47
azul/zulu 7.54
azul/zulu 8.62
azul/zulu 11.56
azul/zulu 13.48
azul/zulu 15.40
azul/zulu 17.34
azul/zulu 18.30
... and 26 more
Published Jul 19, 2022
Tracked Since Feb 18, 2026