Restlet develops a web-framework and API-development platform whose vulnerability footprint centers on XML and deserialization handling in its core framework product, with durable signals pointing to XXE (XML External Entity) references, untrusted deserialization, and related injection issues. These weakness classes reflect the parsing and data-binding demands inherent to a framework that bridges HTTP APIs with structured data formats; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Restlet over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14868HIGH Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP request. This affects use of t | Nov 30, 2017 | 7.5 | 25 | NO | NO |
CVE-2017-14949HIGH Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external ent | Nov 30, 2017 | 7.5 | 24 | NO | NO |
CVE-2013-4271HIGH The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allows remote attackers to execute arbitrary | Oct 10, 2013 | 7.5 | 21 | NO | NO |
CVE-2013-4221HIGH The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources using the Java XMLDecoder, which allows remote attac | Oct 10, 2013 | 7.5 | 20 | NO | NO |
CVE-2014-1868MEDIUM Restlet Framework 2.1.x before 2.1.7 and 2.x.x before 2.2 RC1, when using XMLRepresentation or XML serializers, allows attackers to cause a denial of service via an XML Entity Expa | Oct 6, 2014 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Restlet.
Media articles that mention a CVE ID that affects a product developed by Restlet — matched by CVE ID, not by vendor name.