JVN#40688603
miChecker improper restriction of XML external entity references
Overview
miChecker developed by Eclipse Foundation and provided by Ministry of Internal Affairs and Communications improperly restricts XML external entity references.
Products Affected
- miChecker versions 3.10 and earlier
Description
miChecker developed by Eclipse Foundation and provided by Ministry of Internal Affairs and Communications contains the following vulnerability.
- Improper restriction of XML external entity reference (CWE-611)
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 4.6
- CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N Base Score 3.3
- CVE-2026-14304
Impact
The affected product may communicate unintentionally by reading a crafted subtitle, which may lead local resources or internal network resources to be accessed.
Solution
Update the software
Update the software to the latest version according to the information provided by the developer.
Apply the Workaround
If users cannot update the software to the latest version, the effect of the vulnerability can be avoided by stopping using the "Open caption(SMIL) File" function of the product.
Vendor Status
| Vendor | Link |
| Ministry of Internal Affairs and Communications | miChecker (Text in Japanese) |
| Eclipse Foundation | ACTF - miChecker Vulnerability Information |
| GitHub | eclipse-actf/org.eclipse.actf: ACTF project |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Yuki Matsuhashi reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
|
| JVN iPedia |
JVNDB-2026-000111 |