← Back
CWE-776

85 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.

JSON object

Loading...

CVEs (85)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openvpn
1Openvpn Access Server
Jun 17, 2026
May 4, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
An issue was discovered in OpenVPN Access Server before 2.7.0 and 2.8.x before 2.8.3. With the full featured RPC2 interface enabled, it is possible to achieve a temporary DoS state of the management interface when sendin...Show more
An issue was discovered in OpenVPN Access Server before 2.7.0 and 2.8.x before 2.8.3. With the full featured RPC2 interface enabled, it is possible to achieve a temporary DoS state of the management interface when sending an XML Entity Expansion (XEE) payload to the XMLRPC based RPC2 interface. The duration of the DoS state depends on available memory and CPU speed. The default restricted mode of the RPC2 interface is NOT vulnerable.Show less
1Vmware
1Installbuilder
Jun 17, 2026
Apr 20, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
InstallBuilder AutoUpdate tool and regular installers enabling <checkForUpdates> built with versions earlier than 19.11 are vulnerable to Billion laughs attack (denial-of-service).
1Jenkins
1Code Coverage Api
Jun 17, 2026
Apr 7, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
2Nokogiri
Redhat
8Cloudforms Management Engine
Enterprise MrgNokogiri+5 more
Nov 21, 2024
Feb 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Nokogiri before 1.5.4 is vulnerable to XXE attacks
1Talend
1Restlet
Nov 21, 2024
Feb 19, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe deserialization of XML messages.
1Openpne
1Opopensocialplugin
Nov 21, 2024
Feb 7, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
opOpenSocialPlugin 0.8.2.1, > 0.9.9.2, 0.9.13, 1.2.6: Multiple XML External Entity Injection Vulnerabilities
1Sos Berlin
1Jobscheduler
Jun 17, 2026
Feb 6, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An XML External Entity (XEE) vulnerability exists in the JOC Cockpit component of SOS JobScheduler 1.12 and 1.13.2 allows attackers to read files from the server via an entity declaration in any of the XML documents that...Show more
An XML External Entity (XEE) vulnerability exists in the JOC Cockpit component of SOS JobScheduler 1.12 and 1.13.2 allows attackers to read files from the server via an entity declaration in any of the XML documents that are used to specify the run-time settings of jobs and orders.Show less
1Atlassian
1Crowd
Jun 17, 2026
Feb 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vulnerability.
1Feedgen Project
1Feedgen
Jun 17, 2026
Jan 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Feedgen (python feedgen) before 0.9.0 is susceptible to XML Denial of Service attacks. The *feedgen* library allows supplying XML as content for some of the available fields. This XML will be parsed and integrated into t...Show more
Feedgen (python feedgen) before 0.9.0 is susceptible to XML Denial of Service attacks. The *feedgen* library allows supplying XML as content for some of the available fields. This XML will be parsed and integrated into the existing XML tree. During this process, feedgen is vulnerable to XML Denial of Service Attacks (e.g. XML Bomb). This becomes a concern in particular if feedgen is used to include content from untrused sources and if XML (including XHTML) is directly included instead of providing plain tex content only. This problem has been fixed in feedgen 0.9.0 which disallows XML entity expansion and external resources.Show less
2Fedoraproject
Qt
2Fedora
Qt
Nov 21, 2024
Jan 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.
4Fedoraproject
OracleQuarkus+1 more
4Fedora
Peoplesoft Enterprise Pt PeopletoolsQuarkus+1 more
Nov 21, 2024
Dec 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
3Debian
NokogiriRedhat
7Cloudforms Management Engine
Debian LinuxEnterprise Mrg+4 more
Nov 21, 2024
Nov 5, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
3Debian
NokogiriRedhat
7Cloudforms Management Engine
Debian LinuxEnterprise Mrg+4 more
Nov 21, 2024
Nov 5, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
2Kubernetes
Redhat
2Kubernetes
Openshift Container Platform
Jun 17, 2026
Oct 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API...Show more
Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.Show less
1Apache
1Solr
Jun 17, 2026
Sep 10, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the att...Show more
Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs.Show less
2Libexpat Project
Python
2Libexpat
Python
Jun 17, 2026
Sep 4, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted...Show more
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.Show less
1Kbrw
1Sweet Xml
Jun 17, 2026
Aug 19, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The SweetXml (aka sweet_xml) package through 0.6.6 for Erlang and Elixir allows attackers to cause a denial of service (resource consumption) via an XML entity expansion attack with an inline DTD.
1Pippo
1Pippo
Jun 17, 2026
Jun 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
XML Entity Expansion (Billion Laughs Attack) on Pippo 1.12.0 results in Denial of Service.Entities are created recursively and large amounts of heap memory is taken. Eventually, the JVM process will run out of memory. Ot...Show more
XML Entity Expansion (Billion Laughs Attack) on Pippo 1.12.0 results in Denial of Service.Entities are created recursively and large amounts of heap memory is taken. Eventually, the JVM process will run out of memory. Otherwise, if the OS does not bound the memory on that process, memory will continue to be exhausted and will affect other processes on the system.Show less
3Fedoraproject
MchangeOracle
11C3p0
Communications Ip Service ActivatorCommunications Session Route Manager+8 more
Jun 17, 2026
Apr 22, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
1Apache
1Poi
May 13, 2026
Mar 24, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.