Published:2026/08/17  Last Updated:2026/08/17

JVN#40688603
miChecker improper restriction of XML external entity references

Overview

miChecker developed by Eclipse Foundation and provided by Ministry of Internal Affairs and Communications improperly restricts XML external entity references.

Products Affected

  • miChecker versions 3.10 and earlier

Description

miChecker developed by Eclipse Foundation and provided by Ministry of Internal Affairs and Communications contains the following vulnerability.

  • Improper restriction of XML external entity reference (CWE-611)
    • CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 4.6
    • CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N Base Score 3.3
    • CVE-2026-14304

Impact

The affected product may communicate unintentionally by reading a crafted subtitle, which may lead local resources or internal network resources to be accessed.

Solution

Update the software
Update the software to the latest version according to the information provided by the developer.

Apply the Workaround
If users cannot update the software to the latest version, the effect of the vulnerability can be avoided by stopping using the "Open caption(SMIL) File" function of the product.

Vendor Status

Vendor Link
Ministry of Internal Affairs and Communications miChecker (Text in Japanese)
Eclipse Foundation ACTF - miChecker Vulnerability Information
GitHub | eclipse-actf/org.eclipse.actf: ACTF project

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Yuki Matsuhashi reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia JVNDB-2026-000111