VYPR
Critical severity9.1NVD Advisory· Published Dec 23, 2024· Updated Jun 17, 2026

CVE-2024-40896

CVE-2024-40896

Description

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

55

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.