CWE-776— Improper Restriction of Recursive Entity References (XML Entity Expansion)
70 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-776page 1 of 2
- CVE-2012-3340MEDIUMCVSS 4.3EG 4.32020-09-01
IBM InfoSphere Guardium 8.0, 8.01, and 8.2 is vulnerable to XML external entity injection, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability to obtain sensitive informati…
- CVE-2012-6685HIGHCVSS 7.5EG 7.52020-02-19
Nokogiri before 1.5.4 is vulnerable to XXE attacks
- CVE-2013-4335CRITICALCVSS 9.8EG 9.82020-02-07
opOpenSocialPlugin 0.8.2.1, > 0.9.9.2, 0.9.13, 1.2.6: Multiple XML External Entity Injection Vulnerabilities
- CVE-2013-6460MEDIUMCVSS 6.5EG 6.52019-11-05
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
- CVE-2013-6461MEDIUMCVSS 6.5EG 6.52019-11-05
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
- CVE-2014-2228CRITICALCVSS 9.8EG 9.82020-02-19
The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe deserialization of XML messages.
- CVE-2015-9541HIGHCVSS 7.5EG 7.52020-01-24
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.
- CVE-2017-18640HIGHCVSS 7.5EG 7.52019-12-12
The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
- CVE-2018-10868HIGHCVSS 7.5EG 7.52021-05-26
redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticated user to run a "Billion Laugh Attack" by replying to XMLRPC methods when getting the status of a…
- CVE-2019-11253HIGHCVSS 7.5EG 9.02019-10-17
Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume e…
- CVE-2019-12401HIGHCVSS 7.5EG 7.52019-09-10
Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create …
- CVE-2019-15160HIGHCVSS 7.5EG 7.52019-08-19
The SweetXml (aka sweet_xml) package through 0.6.6 for Erlang and Elixir allows attackers to cause a denial of service (resource consumption) via an XML entity expansion attack with an inline DTD.
- CVE-2019-15903HIGHCVSS 7.5EG 7.52019-09-04
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based bu…
- CVE-2019-20104HIGHCVSS 7.5EG 7.52020-02-06
The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vulnerability.
- CVE-2019-5427HIGHCVSS 7.52019-04-22
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
- CVE-2019-5442HIGHCVSS 7.5EG 7.52019-06-12
XML Entity Expansion (Billion Laughs Attack) on Pippo 1.12.0 results in Denial of Service.Entities are created recursively and large amounts of heap memory is taken. Eventually, the JVM process will run out of memory. Otherwise, if the OS …
- CVE-2020-11462HIGHCVSS 7.5EG 7.52020-05-04
An issue was discovered in OpenVPN Access Server before 2.7.0 and 2.8.x before 2.8.3. With the full featured RPC2 interface enabled, it is possible to achieve a temporary DoS state of the management interface when sending an XML Entity Exp…
- CVE-2020-15303MEDIUMCVSS 6.5EG 6.52021-06-28
Infoblox NIOS before 8.5.2 allows entity expansion during an XML upload operation, a related issue to CVE-2003-1564.
- CVE-2020-2172MEDIUMCVSS 6.5EG 6.52020-04-07
Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2020-24052CRITICALCVSS 9.1EG 9.12020-08-21
Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unauthenticated users to read arbitrary files via a crafted Document Type Definition (DTD) in an XML request.
- CVE-2020-24589CRITICALCVSS 9.1EG 9.12020-08-21
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.
- CVE-2020-24590CRITICALCVSS 9.1EG 9.12020-08-21
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.
- CVE-2020-24591MEDIUMCVSS 6.5EG 6.52020-08-21
The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics 2.2.0 and 2.5.0, API Microgateway 2.2.0, Enterprise Integrator 6.2.0 and 6.3.0, …
- CVE-2020-24665MEDIUMCVSS 6.5EG 6.52021-01-29
The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains an XML Entity Expansion injection vulnerability, which allows an authenticated remote users to trigger a denial of service (DoS) condition. Specifically, the vulner…
- CVE-2020-25186HIGHCVSS 7.5EG 7.52020-10-22
An XXE vulnerability exists within LeviStudioU Release Build 2019-09-21 and prior when processing parameter entities, which may allow file disclosure.
- CVE-2020-27017MEDIUMCVSS 4.9EG 4.92020-11-09
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an XML External Entity Processing (XXE) vulnerability which could allow an authenticated administrator to read arbitrary local files. An attacker must …
- CVE-2020-3946HIGHCVSS 7.5EG 7.52020-04-20
InstallBuilder AutoUpdate tool and regular installers enabling <checkForUpdates> built with versions earlier than 19.11 are vulnerable to Billion laughs attack (denial-of-service).
- CVE-2020-4377CRITICALCVSS 9.1EG 9.12020-08-03
IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM …
- CVE-2020-4481HIGHCVSS 8.2EG 8.22020-08-05
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information o…
- CVE-2020-5227MEDIUMCVSS 4.4EG 4.42020-01-28
Feedgen (python feedgen) before 0.9.0 is susceptible to XML Denial of Service attacks. The *feedgen* library allows supplying XML as content for some of the available fields. This XML will be parsed and integrated into the existing XML tre…
- CVE-2020-6856MEDIUMCVSS 6.5EG 6.52020-02-06
An XML External Entity (XEE) vulnerability exists in the JOC Cockpit component of SOS JobScheduler 1.12 and 1.13.2 allows attackers to read files from the server via an entity declaration in any of the XML documents that are used to specif…
- CVE-2020-9352CRITICALCVSS 9.8EG 9.82020-02-23
An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST request to /tools/developerConsoleOperations.jsp with a valid payload in the _transaction parame…
- CVE-2020-9354HIGHCVSS 7.5EG 7.52020-02-23
An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) saveFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomorphic/IDACall) URL allows an unauthenticated attacker to ove…
- CVE-2021-1267MEDIUMCVSS 4.3EG 4.32021-01-13
A vulnerability in the dashboard widget of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to impro…
- CVE-2021-20453HIGHCVSS 8.2EG 8.22021-04-20
IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory…
- CVE-2021-20464MEDIUMCVSS 6.5EG 6.52022-04-22
IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable to an XML Bomb attack by a malicious authenticated user. IBM X-Force ID: 196813.
- CVE-2021-23926CRITICALCVSS 9.1EG 9.12021-01-14
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and includi…
- CVE-2021-25951HIGHCVSS 7.5EG 7.52021-06-30
XXE vulnerability in 'XML2Dict' version 0.2.2 allows an attacker to cause a denial of service.
- CVE-2021-28302HIGHCVSS 7.5EG 7.52021-03-12
A stack overflow in pupnp before version 1.14.5 can cause the denial of service through the Parser_parseDocument() function. ixmlNode_free() will release a child node recursively, which will consume stack space and lead to a crash.
- CVE-2021-28973MEDIUMCVSS 4.9EG 4.92021-04-13
The XML Import functionality of the Administration console in Perforce Helix ALM 2020.3.1 Build 22 accepts XML input data that is parsed by insecurely configured software components, leading to XXE attacks.
- CVE-2021-31842MEDIUMCVSS 5.0EG 5.52021-09-17
XML Entity Expansion injection vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2021 Update allows a local user to initiate high CPU and memory consumption resulting in a Denial of Service attack throug…
- CVE-2021-32623HIGHCVSS 8.1EG 8.12021-06-16
Opencast is a free and open source solution for automated video capture and distribution. Versions of Opencast prior to 9.6 are vulnerable to the billion laughs attack, which allows an attacker to easily execute a (seemingly permanent) den…
- CVE-2021-3541MEDIUMCVSS 6.5EG 6.52021-07-09
A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.
- CVE-2021-38490HIGHCVSS 7.5EG 7.52021-08-10
Altova MobileTogether Server before 7.3 SP1 allows XML exponential entity expansion, a different vulnerability than CVE-2021-37425.
- CVE-2021-40511HIGHCVSS 7.5EG 7.52022-06-21
OBDA systems’ Mastro 1.0 is vulnerable to XML Entity Expansion (aka “billion laughs”) attack allowing denial of service.
- CVE-2021-41559MEDIUMCVSS 6.5EG 6.52022-06-28
Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.
- CVE-2022-0217HIGHCVSS 7.5EG 7.52022-08-26
It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in expansion of recursive entity reference…
- CVE-2022-23640CRITICALCVSS 9.8EG 9.82022-03-02
Excel-Streaming-Reader is an easy-to-use implementation of a streaming Excel reader using Apache POI. Prior to xlsx-streamer 2.1.0, the XML parser that was used did apply all the necessary settings to prevent XML Entity Expansion issues. U…
- CVE-2022-25857HIGHCVSS 7.5EG 7.52022-08-30
The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.
- CVE-2022-26662HIGHCVSS 7.5EG 7.52022-03-10
An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x throu…
Map vulnerabilities like CWE-776 to your infrastructure
EchelonGraph correlates every CVE — across CWE-776 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →