CWE-776— Improper Restriction of Recursive Entity References (XML Entity Expansion)
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.— MITRE CWE catalog
104 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-776page 3 of 3
- CVE-2026-45304HIGHCVSS 7.5EG 7.52026-05-27
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser resolved YAML collection aliases recursively, allowing a small unt…
- CVE-2026-45771HIGHCVSS 7.5EG 7.52026-06-09
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, FreeSWITCH's bundled XML parser…
- CVE-2026-73569HIGHCVSS 8.7EG 8.72026-07-21
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From 5.9.3 until 5.10.1, src/xmlparser/OrderedObjParser.js processes multiple DOCTYPE declarations within a single XML document and pass…
- CVE-2026-78681HIGHCVSS 7.5EG 7.52026-08-25
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations in document DTDs. Attackers can craft XML payloads with nested entity declarations that expand from hundreds of bytes …
Map vulnerabilities like CWE-776 to your infrastructure
EchelonGraph correlates every CVE — across CWE-776 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →