Checkstyle is a static code-analysis tool for Java that validates source code against a configurable set of style and quality rules, with a narrow but widely adopted footprint in development pipelines. The observed vulnerability signal centers on XML external entity reference handling, reflecting the product's configuration and reporting mechanisms that parse XML input.
The number and severity of CVEs published that impact products developed by Checkstyle over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10782MEDIUM All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658. | Jan 30, 2020 | 5.3 | 20 | NO | NO |
CVE-2019-9658MEDIUM Checkstyle before 8.18 loads external DTDs by default. | Mar 11, 2019 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Checkstyle.
Media articles that mention a CVE ID that affects a product developed by Checkstyle — matched by CVE ID, not by vendor name.