VYPR

CWE-776

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

BaseDraftLikelihood: Medium

Description

The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.

If the DTD contains a large number of nested or recursive entities, this can lead to explosive growth of data when parsed, causing a denial of service.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-197

CVEs mapped to this weakness (105)

page 1 of 6
  • CVE-2019-19144CriAug 1, 2025
    risk 0.64cvss 9.8epss 0.01

    XML External Entity Injection vulnerability in Quantum DXi6702 2.3.0.3 (11449-53631 Build304) devices via rest/Users?action=authenticate.

  • CVE-2014-2228CriFeb 19, 2020
    risk 0.64cvss 9.8epss 0.03

    The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe deserialization of XML messages.

  • CVE-2021-23926CriJan 14, 2021
    risk 0.60cvss 9.1epss 0.06

    The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

  • CVE-2024-37388CriJun 7, 2024
    risk 0.59cvss 9.1epss 0.01

    An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers to access sensitive information or cause a Denial of Service (DoS) via crafted XML input.

  • CVE-2020-24590CriAug 21, 2020
    risk 0.59cvss 9.1epss 0.01

    The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.

  • CVE-2026-3415HigAug 6, 2026
    risk 0.57cvss 8.7epss 0.00

    The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validation flows. Under certain conditions, the XML parser allows the resolution of external entities when handling user-supplied XML content during validation…

  • CVE-2023-24443CriJan 26, 2023
    risk 0.57cvss 9.8epss 0.01

    Jenkins TestComplete support Plugin 2.8.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2023-24441CriJan 26, 2023
    risk 0.57cvss 9.8epss 0.01

    Jenkins MSTest Plugin 1.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-23640CriMar 2, 2022
    risk 0.57cvss 9.8epss 0.01

    Excel-Streaming-Reader is an easy-to-use implementation of a streaming Excel reader using Apache POI. Prior to xlsx-streamer 2.1.0, the XML parser that was used did apply all the necessary settings to prevent XML Entity Expansion issues. Upgrade to version 2.1.0 to receive a…

  • CVE-2013-4335CriFeb 7, 2020
    risk 0.57cvss 9.8epss 0.02

    opOpenSocialPlugin 0.8.2.1, > 0.9.9.2, 0.9.13, 1.2.6: Multiple XML External Entity Injection Vulnerabilities

  • CVE-2017-18640HigDec 12, 2019
    risk 0.51cvss 7.5epss 0.27

    The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.

  • CVE-2026-73569HigAug 13, 2026
    risk 0.50cvss epss 0.00

    fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From 5.9.3 until 5.10.1, src/xmlparser/OrderedObjParser.js processes multiple DOCTYPE declarations within a single XML document and passes each declaration's entities through…

  • CVE-2026-31248HigMay 11, 2026
    risk 0.49cvss 7.5epss 0.00

    Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend extracts and validates XML files from .tar.gz archives using etree.fromstring() without disabling entity resolution. An attacker can craft a malicious XML file with nested…

  • CVE-2024-36827HigJun 7, 2024
    risk 0.49cvss 7.5epss 0.01

    An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of ebookmeta before v1.2.8 allows attackers to access sensitive information or cause a Denial of Service (DoS) via crafted XML input.

  • CVE-2023-49967HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc.

  • CVE-2023-49735HigNov 30, 2023
    risk 0.49cvss 7.5epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML definition files, leading to possible path traversal and eventually SSRF/XXE when passing user-controlled data to this key.…

  • CVE-2022-0217HigAug 26, 2022
    risk 0.49cvss 7.5epss 0.05

    It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in expansion of recursive entity references from DTDs (CWE-776). In addition,…

  • CVE-2021-40511HigJun 21, 2022
    risk 0.49cvss 7.5epss 0.01

    OBDA systems’ Mastro 1.0 is vulnerable to XML Entity Expansion (aka “billion laughs”) attack allowing denial of service.

  • CVE-2022-26662HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.02

    An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x…

  • CVE-2021-38490HigAug 10, 2021
    risk 0.49cvss 7.5epss 0.01

    Altova MobileTogether Server before 7.3 SP1 allows XML exponential entity expansion, a different vulnerability than CVE-2021-37425.