CWE-776— Improper Restriction of Recursive Entity References (XML Entity Expansion)
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.— MITRE CWE catalog
109 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-776page 2 of 3
- CVE-2019-20104HIGHCVSS 7.5EG 7.52020-02-06
The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vulnerability.
- CVE-2015-9541HIGHCVSS 7.5EG 7.52020-01-24
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.
- CVE-2017-18640HIGHCVSS 7.5EG 7.52019-12-12
The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
- CVE-2019-11253HIGHCVSS 7.5EG 7.52019-10-17
Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume e…
- CVE-2019-12401HIGHCVSS 7.5EG 7.52019-09-10
Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create …
- CVE-2019-15903HIGHCVSS 7.5EG 7.52019-09-04
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based bu…
- CVE-2019-15160HIGHCVSS 7.5EG 7.52019-08-19
The SweetXml (aka sweet_xml) package through 0.6.6 for Erlang and Elixir allows attackers to cause a denial of service (resource consumption) via an XML entity expansion attack with an inline DTD.
- CVE-2019-5442HIGHCVSS 7.5EG 7.52019-06-12
XML Entity Expansion (Billion Laughs Attack) on Pippo 1.12.0 results in Denial of Service.Entities are created recursively and large amounts of heap memory is taken. Eventually, the JVM process will run out of memory. Otherwise, if the OS …
- CVE-2019-5427HIGHCVSS 7.5EG 7.52019-04-22
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
- CVE-2011-3288HIGHCVSS 7.5EG 7.52011-10-06
Cisco Unified Presence before 8.5(4) does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption, and process crash) via a crafted XML document containi…
- CVE-2011-1755HIGHCVSS 7.5EG 7.52011-06-21
jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entit…
- CVE-2022-34430HIGHCVSS 7.1EG 7.52022-10-11
Dell Hybrid Client below 1.8 version contains a Zip Bomb Vulnerability in UI. A guest privilege attacker could potentially exploit this vulnerability, leading to system files modification.
- CVE-2026-54077HIGHCVSS 7.1EG 7.12026-07-16
ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/query/sql/parser/ImportDatabaseStatement.java did not require administrative privileges and passed its source to integratio…
- CVE-2026-44018HIGHCVSS 7.1EG 7.12026-06-03
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the input document format detection lacked secu…
- CVE-2026-42212HIGHCVSS 7.1EG 7.12026-05-08
SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, Opening a .gpp file in the SolidCAM Postprocessor IDE extension causes the language server t…
- CVE-2024-28982HIGHCVSS 7.1EG 7.12024-06-26
Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.
- CVE-2023-38490MEDIUMCVSS 6.8EG 6.82023-07-27
Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 only affects Kirby sites that use the `Xml` data handler (e.g. `Data::decode($string, 'xml')`) or the `Xml::parse()` m…
- CVE-2026-12993MEDIUMCVSS 6.5EG 6.52026-06-26
A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE declarations or enable FEATURE_SECURE_PROCESSING. An attacker with artifact-write permission ca…
- CVE-2023-41635MEDIUMCVSS 6.5EG 6.52023-08-31
A XML External Entity (XXE) vulnerability in the VerifichePeriodiche.aspx component of GruppoSCAI RealGimm v1.1.37p38 allows attackers to read any file in the filesystem via supplying a crafted XML file.
- CVE-2022-44641MEDIUMCVSS 6.5EG 6.52022-11-18
In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recursive XML entity expansion, leading to excessive use of memory on the server and a Denial o…
- CVE-2022-34467MEDIUMCVSS 6.5EG 6.52022-07-12
A vulnerability has been identified in Mendix Excel Importer Module (Mendix 8 compatible) (All versions < V9.2.2), Mendix Excel Importer Module (Mendix 9 compatible) (All versions < V10.1.2). The affected component is vulnerable to XML Ent…
- CVE-2021-41559MEDIUMCVSS 6.5EG 6.52022-06-28
Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.
- CVE-2021-20464MEDIUMCVSS 6.5EG 6.52022-04-22
IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable to an XML Bomb attack by a malicious authenticated user. IBM X-Force ID: 196813.
- CVE-2021-3541MEDIUMCVSS 6.5EG 6.52021-07-09
A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.
- CVE-2020-15303MEDIUMCVSS 6.5EG 6.52021-06-28
Infoblox NIOS before 8.5.2 allows entity expansion during an XML upload operation, a related issue to CVE-2003-1564.
- CVE-2020-24665MEDIUMCVSS 6.5EG 6.52021-01-29
The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains an XML Entity Expansion injection vulnerability, which allows an authenticated remote users to trigger a denial of service (DoS) condition. Specifically, the vulner…
- CVE-2020-24591MEDIUMCVSS 6.5EG 6.52020-08-21
The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager Analytics 2.2.0 and 2.5.0, API Microgateway 2.2.0, Enterprise Integrator 6.2.0 and 6.3.0, …
- CVE-2020-2172MEDIUMCVSS 6.5EG 6.52020-04-07
Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2020-6856MEDIUMCVSS 6.5EG 6.52020-02-06
An XML External Entity (XEE) vulnerability exists in the JOC Cockpit component of SOS JobScheduler 1.12 and 1.13.2 allows attackers to read files from the server via an entity declaration in any of the XML documents that are used to specif…
- CVE-2013-6461MEDIUMCVSS 6.5EG 6.52019-11-05
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
- CVE-2013-6460MEDIUMCVSS 6.5EG 6.52019-11-05
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
- CVE-2008-3281MEDIUMCVSS 6.5EG 6.52008-08-27
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
- CVE-2003-1564MEDIUMCVSS 6.5EG 6.52003-12-31
libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large nu…
- CVE-2026-92001MEDIUMCVSS 6.1EG 6.12026-09-23
Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fix…
- CVE-2023-46035MEDIUMCVSS 5.9EG 5.92026-09-14
The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.
- CVE-2025-0617MEDIUMCVSS 5.9EG 5.92025-01-29
An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger file parsing containing exponential entity expansions in the consumer process th…
- CVE-2024-43398MEDIUMCVSS 5.9EG 5.92024-08-22
REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like REXM…
- CVE-2024-27142MEDIUMCVSS 5.9EG 5.92024-06-14
Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable to a time-based blind XML External Entity (XXE) vulnerability. An attacker can DoS the …
- CVE-2024-27141MEDIUMCVSS 5.9EG 5.92024-06-14
Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable to a time-based blind XML External Entity (XXE) vulnerability. An attacker can DoS the …
- CVE-2024-1455MEDIUMCVSS 5.9EG 5.92024-03-26
A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nesting multiple layers of entities within an XML document, an attacker can cause the XML par…
- CVE-2026-16180MEDIUMCVSS 5.7EG 5.72026-09-04
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 Toolkit could allow an authenticated user to cause a denial-of-service condition due to improp…
- CVE-2022-28652MEDIUMCVSS 5.5EG 5.52024-06-04
~/.config/apport/settings parsing is vulnerable to "billion laughs" attack
- CVE-2023-52426MEDIUMCVSS 5.5EG 5.52024-02-04
libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.
- CVE-2017-5644MEDIUMCVSS 5.5EG 5.52017-03-24
Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
- CVE-2021-31842MEDIUMCVSS 5.0EG 5.52021-09-17
XML Entity Expansion injection vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2021 Update allows a local user to initiate high CPU and memory consumption resulting in a Denial of Service attack throug…
- CVE-2026-14865MEDIUMCVSS 5.3EG 5.32026-07-22
In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity expansion.
- CVE-2026-23822MEDIUMCVSS 5.3EG 5.32026-05-12
A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an attacker to cause excessive resource consu…
- CVE-2026-40260MEDIUMCVSS 5.3EG 5.32026-04-17
pypdf is a free and open-source pure-python PDF library. In versions prior to 6.10.0, manipulated XMP metadata entity declarations can exhaust RAM. An attacker who exploits this vulnerability can craft a PDF which leads to large memory usa…
- CVE-2023-20052MEDIUMCVSS 5.3EG 5.32023-03-01
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauth…
- CVE-2026-27807MEDIUMCVSS 4.9EG 4.92026-03-06
MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.4, MarkUs allows course instructors to upload YAML files to create/update various entities (e.g., assignment settings). These YAML file…
Map vulnerabilities like CWE-776 to your infrastructure
EchelonGraph correlates every CVE — across CWE-776 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →