diff --git a/modules/core/src/main/java/org/apache/synapse/mediators/transform/pfutils/TemplateProcessor.java b/modules/core/src/main/java/org/apache/synapse/mediators/transform/pfutils/TemplateProcessor.java index d7d5f65e5e..097063a4f1 100644 --- a/modules/core/src/main/java/org/apache/synapse/mediators/transform/pfutils/TemplateProcessor.java +++ b/modules/core/src/main/java/org/apache/synapse/mediators/transform/pfutils/TemplateProcessor.java @@ -533,6 +533,7 @@ protected void handleException(String msg) { public void readInputFactoryProperties() { //ignore DTDs for XML Input inputFactory.setProperty(XMLInputFactory.SUPPORT_DTD, Boolean.FALSE); + inputFactory.setProperty(XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, Boolean.FALSE); inputFactory.setProperty(XMLInputFactory.IS_COALESCING, true); Map props = StAXUtils.loadFactoryProperties("XMLInputFactory.properties"); if (props != null) {