<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Mule Runtime</title>
  <link>https://cvedaily.com/pages/tags/mulesoft-runtime.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/mulesoft-runtime.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Mule Runtime</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:11 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2021-1630 – XML external entity (XXE) vulnerability affecting certain versions of a Mule run...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1630</guid>
    <pubDate>Thu, 05 Aug 2021 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1630</strong></p>
  <p>XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pivotal Cloud Foundry, Private Cloud Edition, and on-premise customers.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-1628 – MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1628</guid>
    <pubDate>Fri, 26 Mar 2021 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-1628</strong></p>
  <p>MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Affected versions: Mule 4.x runtime released before February 2, 2021.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-1627 – MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1627</guid>
    <pubDate>Fri, 26 Mar 2021 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-1627</strong></p>
  <p>MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. This affects: Mule 3.8.x,3.9.x,4.x runtime released before February 2, 2021.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-1626 – MuleSoft is aware of a Remote Code Execution vulnerability affecting certain ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1626</guid>
    <pubDate>Fri, 26 Mar 2021 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-1626</strong></p>
  <p>MuleSoft is aware of a Remote Code Execution vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Versions affected: Mule 4.1.x and 4.2.x runtime released before February 2, 2021.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15630 – Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15630</guid>
    <pubDate>Fri, 30 Aug 2019 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15630</strong></p>
  <p>Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 and higher released before August 1 2019, and all versions of MuleSoft API Gateway released before August 1 2019 allow remote attackers to read files accessible to the Mule process.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15630">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
