CWE-776
85 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
CVEs (85)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ivanti 4Connect Secure Neurons For Secure AccessPolicy Secure+1 moreJun 17, 2026 Aug 12, 2025 N/A· v4 4.9 MEDIUM· v3 N/A· v2 XEE in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allo...Show more |
XML External Entity Injection vulnerability in Quantum DXi6702 2.3.0.3 (11449-53631 Build304) devices via rest/Users?action=authenticate. |
An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-llama/llama_index repository, specifically affecting version v0.12.21. This vulnerability allows an...Show more |
An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger file parsing containing exponential entity expansions in the...Show more |
2Netapp Ruby Lang2Bootstrap Os RexmlJun 17, 2026 Aug 22, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree p...Show more |
1Hitachi 1Pentaho Business Analytics Server Jun 17, 2026 Jun 26, 2024 N/A· v4 8.2 HIGH· v3 N/A· v2 Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference. |
Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable to a time-based blind XML External Entity (XXE) vulnerability. An at...Show more |
Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable to a time-based blind XML External Entity (XXE) vulnerability. An at...Show more |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Jun 4, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 ~/.config/apport/settings parsing is vulnerable to "billion laughs" attack |
A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nesting multiple layers of entities within an XML document, an attacker ca...Show more |
3Fedoraproject Libexpat ProjectNetapp14Active Iq Unified Manager FedoraH300s Firmware+11 moreJun 17, 2026 Mar 10, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate). |
libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time. |
Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc. |
A XML External Entity (XXE) vulnerability in the VerifichePeriodiche.aspx component of GruppoSCAI RealGimm v1.1.37p38 allows attackers to read any file in the filesystem via supplying a crafted XML file. |
1Phoenixcontact 7Cloud Client 1101t Tx Firmware Tc Cloud Client 1002 4g Att FirmwareTc Cloud Client 1002 4g Firmware+4 moreJun 17, 2026 Aug 8, 2023 N/A· v4 4.9 MEDIUM· v3 N/A· v2 In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload a crafted XML file w...Show more |
Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 only affects Kirby sites that use the `Xml` data handler (e.g. `Data::decode($string, 'xml')`) or t...Show more |
kaml provides YAML support for kotlinx.serialization. Prior to version 0.53.0, applications that use kaml to parse untrusted input containing anchors and aliases may consume excessive memory and crash. Version 0.53.0 and...Show more |
3Cisco ClamavStormshield4Clamav Secure EndpointSecure Endpoint Private Cloud+1 moreJun 17, 2026 Mar 1, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier co...Show more |
In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recursive XML entity expansion, leading to excessive use of memory on the se...Show more |
Dell Hybrid Client below 1.8 version contains a Zip Bomb Vulnerability in UI. A guest privilege attacker could potentially exploit this vulnerability, leading to system files modification. |