Skip to content

[Eclipse 2026-09] New Java 25 XML limits cause problems with some plugins which process large XML files #2917

Description

@chrisrueger

In bndtools we discovered that with new new Eclipse 2026-09 released today bndtools is not working properly because in our specific instance there is a repository configured which processes a large XML OSGI index which exceeds Java 25 internal xml limits.

e.g.

Caused by: javax.xml.stream.XMLStreamException: ParseError at [row,col]:[263628,258]
Message: JAXP00010003: Die Länge von Entity "[xml]" ist "100.001" und überschreitet den Grenzwert "100.000", der von "jdk.xml.maxGeneralEntitySizeLimit" festgelegt wurde.
	at java.xml/com.sun.org.apache.xerces.internal.impl.XMLStreamReaderImpl.next(XMLStreamReaderImpl.java:652)
	at java.xml/com.sun.org.apache.xerces.internal.impl.XMLStreamReaderImpl.nextTag(XMLStreamReaderImpl.java:1353)
	at aQute.bnd.osgi.repository.XMLResourceParser.next(XMLResourceParser.java:193)

See for details and workaround bndtools/bnd#7412

Workaround:

set the following in eclipse.ini of the Eclipse instance you are running:

-Djdk.xml.maxGeneralEntitySizeLimit=0
-Djdk.xml.entityExpansionLimit=0
-Djdk.xml.totalEntitySizeLimit=0

or any other reasonably high value if you think 0 (unlimited) is too dangerous.

Question

Is there something Eclipse should do?
or plugin authors? (e.g. for bndtools we could set the limits directly on the XMLInputFactory but this would not work for older releases of our plugin.

In case this is the wrong repo for this issue, just let me know where I can move it to.

Activity

  1. merks commented on Sep 9, 2026

    @merks
    Contributor

    For p2, it sets some of those here:

    https://github.com/eclipse-equinox/p2/blob/919d7f33c451e19ca69a17b80281c3a7b253d4c8/bundles/org.eclipse.equinox.p2.repository/src/org/eclipse/equinox/internal/p2/persistence/XMLParser.java#L98-L109

    I'm not sure entityExpansionLimit is needed?

    I think the danger of these is overrated, but hey we're all entitled to an opinion. After all, this content is being used to load repositories from which the user is going to install bundles. So what, you're kill my process with some evil XML overload before I get a chance to install your evil content rather than encourage me to proceed and actually install said evil content and then run it in the JVM after it restarts at which point the evil I can do is way more than exploding your XML processor.

  2. locked and limited conversation to collaborators on Sep 9, 2026
  3. converted this issue into a discussion #2918 on Sep 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions