maven›com.github.wxpay/wxpay-sdk›CVE-2018-134397.5 HIGHImproper Restriction of XML External Entity ReferenceWXPayUtil in WeChat Pay Java SDK allows XXE attacks involving a merchant notification URL.