VYPR

CWE-776

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

BaseDraftLikelihood: Medium

Description

The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.

If the DTD contains a large number of nested or recursive entities, this can lead to explosive growth of data when parsed, causing a denial of service.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-197

CVEs mapped to this weakness (105)

page 4 of 6
  • CVE-2021-3541MedJul 9, 2021
    risk 0.42cvss 6.5epss 0.02

    A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.

  • CVE-2020-15303MedJun 28, 2021
    risk 0.42cvss 6.5epss 0.01

    Infoblox NIOS before 8.5.2 allows entity expansion during an XML upload operation, a related issue to CVE-2003-1564.

  • CVE-2020-24665MedJan 29, 2021
    risk 0.42cvss 6.5epss 0.01

    The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains an XML Entity Expansion injection vulnerability, which allows an authenticated remote users to trigger a denial of service (DoS) condition. Specifically, the vulnerability lies in the 'dashboardXml'…

  • CVE-2020-6856MedFeb 6, 2020
    risk 0.42cvss 6.5epss 0.01

    An XML External Entity (XEE) vulnerability exists in the JOC Cockpit component of SOS JobScheduler 1.12 and 1.13.2 allows attackers to read files from the server via an entity declaration in any of the XML documents that are used to specify the run-time settings of jobs and…

  • CVE-2013-6461MedNov 5, 2019
    risk 0.42cvss 6.5epss 0.02

    Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits

  • CVE-2013-6460MedNov 5, 2019
    risk 0.42cvss 6.5epss 0.02

    Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents

  • CVE-2008-3281MedAug 27, 2008
    risk 0.42cvss 6.5epss 0.03

    libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.

  • CVE-2003-1564MedDec 31, 2003
    risk 0.42cvss 6.5epss 0.02

    libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka…

  • CVE-2026-42212HigMay 8, 2026
    risk 0.39cvss epss 0.00

    SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, Opening a .gpp file in the SolidCAM Postprocessor IDE extension causes the language server to parse a companion .vmid file from the…

  • CVE-2025-0617MedJan 29, 2025
    risk 0.38cvss 5.9epss 0.00

    An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger file parsing containing exponential entity expansions in the consumer process thus causing a Denial of Service.

  • CVE-2024-27142MedJun 14, 2024
    risk 0.38cvss 5.9epss 0.01

    Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable to a time-based blind XML External Entity (XXE) vulnerability. An attacker can DoS the printers. An attacker can exploit the…

  • CVE-2024-27141MedJun 14, 2024
    risk 0.38cvss 5.9epss 0.01

    Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable to a time-based blind XML External Entity (XXE) vulnerability. An attacker can DoS the printers by sending a HTTP request…

  • CVE-2023-38490MedJul 27, 2023
    risk 0.37cvss 6.8epss 0.02

    Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 only affects Kirby sites that use the `Xml` data handler (e.g. `Data::decode($string, 'xml')`) or the `Xml::parse()` method in site or plugin code. The Kirby…

  • CVE-2022-28652MedJun 4, 2024
    risk 0.36cvss 5.5epss 0.00

    ~/.config/apport/settings parsing is vulnerable to "billion laughs" attack

  • CVE-2017-5644MedMar 24, 2017
    risk 0.36cvss 5.5epss 0.05

    Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.

  • CVE-2023-20052MedMar 1, 2023
    risk 0.35cvss 5.3epss 0.07

    On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access…

  • CVE-2020-2172MedApr 7, 2020
    risk 0.35cvss 6.5epss 0.01

    Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2026-14865MedJul 22, 2026
    risk 0.34cvss 5.3epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity expansion.

  • CVE-2026-14979MedJul 17, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOORS could allow a remote attacker to cause a denial of service due to improper handling of XML entity…

  • CVE-2026-23822MedMay 12, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an attacker to cause excessive resource consumption upon user interaction, leading to…