From d8932b7abfbfc3e2aa00254ae027fc656dc7ac34 Mon Sep 17 00:00:00 2001 From: Vladimir Krivosheev Date: Mon, 9 Feb 2026 17:04:07 +0100 Subject: [PATCH] IJPL-159489 jewel: harden XML resource parsing GitOrigin-RevId: e09c266010aa8664920d2ba59cc904c142680442 --- .../jewel/ui/painter/ResourcePainterProvider.kt | 15 ++++++++++++++- 1 file changed, 14 insertions(+), 1 deletion(-) diff --git a/platform/jewel/ui/src/main/kotlin/org/jetbrains/jewel/ui/painter/ResourcePainterProvider.kt b/platform/jewel/ui/src/main/kotlin/org/jetbrains/jewel/ui/painter/ResourcePainterProvider.kt index 3081541ad709..da5b6340b5c1 100644 --- a/platform/jewel/ui/src/main/kotlin/org/jetbrains/jewel/ui/painter/ResourcePainterProvider.kt +++ b/platform/jewel/ui/src/main/kotlin/org/jetbrains/jewel/ui/painter/ResourcePainterProvider.kt @@ -50,8 +50,21 @@ public class ResourcePainterProvider(private val basePath: String, vararg classL private val cache = ConcurrentHashMap() + @Suppress("HttpUrlsUsage") private val documentBuilderFactory = - DocumentBuilderFactory.newDefaultInstance().apply { setFeature(XMLConstants.FEATURE_SECURE_PROCESSING, true) } + DocumentBuilderFactory.newDefaultInstance().apply { + isValidating = false + setFeature(XMLConstants.FEATURE_SECURE_PROCESSING, true) + setFeature("http://apache.org/xml/features/disallow-doctype-decl", true) + setFeature("http://xml.org/sax/features/external-general-entities", false) + setFeature("http://xml.org/sax/features/external-parameter-entities", false) + setFeature("http://apache.org/xml/features/nonvalidating/load-dtd-grammar", false) + setFeature("http://apache.org/xml/features/nonvalidating/load-external-dtd", false) + setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "") + setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, "") + isXIncludeAware = false + isExpandEntityReferences = false + } private fun Scope.resolveHint(hint: PainterHint) { with(hint) {