CVE-2021-1630
XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pivotal Cloud Foundry, Private Cloud Edition, and on…
All CVEs associated with "Mule Runtime". Page 1/1 • 5 CVEs.
A curated feed of “Mule Runtime”-related CVEs appears below. We currently track 5 CVEs for this tag (all time). In the last 365 days, 0 were published. Average CVSS is 8.9 (all time), and 100% are rated High/Critical (all time). Top CWEs (all time): CWE-611 - Improper Restriction of XML External Entity Reference, CWE-918 - Server-Side Request Forgery (SSRF), CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal').
In our taxonomy this topic maps to a LOW impact class. Integration platforms and ESBs bridge systems. Patch runtimes and connectors, restrict admin consoles, validate signer keys, and monitor flows. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.
This table shows recent release cycles and their projected end-of-life. Data source: endoflife.date.
| Cycle | Release | Latest | Premier Support | EOL | LTS |
|---|---|---|---|---|---|
| 4.11 | 4.11.2 | Soon | |||
| 4.10 | 4.10.5 | Soon | |||
| 4.9-lts | 4.9.16 | LTS | |||
| 4.9 | 4.9.16 | Expired | |||
| 4.8 | 4.8.6 | Expired | |||
| 4.7 | 4.7.4 | Expired | |||
| 4.6-lts | 4.6.22 | ||||
| 4.6 | 4.6.22 | Expired | |||
| 4.5 | 4.5.3 | Expired | |||
| 4.4 | 4.4.0-20250919 | Expired | |||
| 4.3 | 4.3.0-20240424 | Expired | |||
| 4.2 | 4.2.2-20221027 | Expired | |||
| 4.1 | 4.1.6-20240112 | Expired | |||
| 3.9 | 3.9.5-20240122 | Expired | LTS | ||
| 3.8 | 3.8.7 | Expired | LTS |
Maintained Soon (≤ 180 days) Expired
Subscribe lifecycle: RSS · RSS (expired) · ICS
Subscribe CVEs: RSS for “Mule Runtime” · RSS (High+Critical only)
CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).
XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pivotal Cloud Foundry, Private Cloud Edition, and on…
MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Affected versions: Mule 4…
MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. This affects: Mule 3.8.…
MuleSoft is aware of a Remote Code Execution vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Versions affected: Mule 4.1.x…
Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 and higher released…