CWE-776— Improper Restriction of Recursive Entity References (XML Entity Expansion)
84 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-776page 2 of 2
- CVE-2021-40511HIGHCVSS 7.5EG 7.52022-06-21
OBDA systems’ Mastro 1.0 is vulnerable to XML Entity Expansion (aka “billion laughs”) attack allowing denial of service.
- CVE-2021-41559MEDIUMCVSS 6.5EG 6.52022-06-28
Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack via a crafted XML document.
- CVE-2022-0217HIGHCVSS 7.5EG 7.52022-08-26
It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in expansion of recursive entity reference…
- CVE-2022-23640CRITICALCVSS 9.8EG 9.82022-03-02
Excel-Streaming-Reader is an easy-to-use implementation of a streaming Excel reader using Apache POI. Prior to xlsx-streamer 2.1.0, the XML parser that was used did apply all the necessary settings to prevent XML Entity Expansion issues. U…
- CVE-2022-25857HIGHCVSS 7.5EG 7.52022-08-30
The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.
- CVE-2022-26662HIGHCVSS 7.5EG 7.52022-03-10
An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x throu…
- CVE-2022-28652MEDIUMCVSS 5.5EG 5.52024-06-04
~/.config/apport/settings parsing is vulnerable to "billion laughs" attack
- CVE-2022-33977HIGHCVSS 7.5EG 7.52022-07-26
untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts recursive entity references in DTDs. By exploiting this vulnerability, a remote unauthenticated attacker may cause…
- CVE-2022-34430HIGHCVSS 7.1EG 7.52022-10-11
Dell Hybrid Client below 1.8 version contains a Zip Bomb Vulnerability in UI. A guest privilege attacker could potentially exploit this vulnerability, leading to system files modification.
- CVE-2022-34467MEDIUMCVSS 6.5EG 6.52022-07-12
A vulnerability has been identified in Mendix Excel Importer Module (Mendix 8 compatible) (All versions < V9.2.2), Mendix Excel Importer Module (Mendix 9 compatible) (All versions < V10.1.2). The affected component is vulnerable to XML Ent…
- CVE-2022-42745HIGHCVSS 7.5EG 7.52022-11-03
CandidATS version 3.0.0 allows an external attacker to read arbitrary files from the server. This is possible because the application is vulnerable to XXE.
- CVE-2022-44641MEDIUMCVSS 6.5EG 6.52022-11-18
In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recursive XML entity expansion, leading to excessive use of memory on the server and a Denial o…
- CVE-2023-20052MEDIUMCVSS 5.3EG 5.32023-03-01
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauth…
- CVE-2023-28118HIGHCVSS 7.5EG 7.52023-03-20
kaml provides YAML support for kotlinx.serialization. Prior to version 0.53.0, applications that use kaml to parse untrusted input containing anchors and aliases may consume excessive memory and crash. Version 0.53.0 and later default to r…
- CVE-2023-3569MEDIUMCVSS 4.9EG 4.92023-08-08
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload a crafted XML file which causes a denia…
- CVE-2023-38490MEDIUMCVSS 6.8EG 6.82023-07-27
Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 only affects Kirby sites that use the `Xml` data handler (e.g. `Data::decode($string, 'xml')`) or the `Xml::parse()` m…
- CVE-2023-41635MEDIUMCVSS 6.5EG 6.52023-08-31
A XML External Entity (XXE) vulnerability in the VerifichePeriodiche.aspx component of GruppoSCAI RealGimm v1.1.37p38 allows attackers to read any file in the filesystem via supplying a crafted XML file.
- CVE-2023-49735HIGHCVSS 7.5EG 7.52023-11-30
** UNSUPPORTED WHEN ASSIGNED ** The value set as the DefaultLocaleResolver.LOCALE_KEY attribute on the session was not validated while resolving XML definition files, leading to possible path traversal and eventually SSRF/XXE when passing…
- CVE-2023-49967HIGHCVSS 7.5EG 7.52023-12-07
Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc.
- CVE-2023-52426MEDIUMCVSS 5.5EG 5.52024-02-04
libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.
- CVE-2024-1455MEDIUMCVSS 5.9EG 5.92024-03-26
A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nesting multiple layers of entities within an XML document, an attacker can cause the XML par…
- CVE-2024-27141MEDIUMCVSS 5.9EG 5.92024-06-14
Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable to a time-based blind XML External Entity (XXE) vulnerability. An attacker can DoS the …
- CVE-2024-27142MEDIUMCVSS 5.9EG 5.92024-06-14
Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable to a time-based blind XML External Entity (XXE) vulnerability. An attacker can DoS the …
- CVE-2024-28757HIGHCVSS 7.5EG 7.52024-03-10
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
- CVE-2024-28982HIGHCVSS 7.1EG 7.12024-06-26
Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.
- CVE-2024-43398MEDIUMCVSS 5.9EG 5.92024-08-22
REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree parser API like REXM…
- CVE-2025-0617MEDIUMCVSS 5.9EG 5.92025-01-29
An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger file parsing containing exponential entity expansions in the consumer process th…
- CVE-2025-20369MEDIUMCVSS 4.6EG 4.62025-10-01
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privilege user that does not hold the "admin" or "power" Splunk roles could perform an…
- CVE-2025-3225HIGHCVSS 7.5EG 7.52025-07-07
An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-llama/llama_index repository, specifically affecting version v0.12.21. This vulnerability allows an attacker to supply …
- CVE-2025-5466MEDIUMCVSS 4.9EG 4.92025-08-12
XEE in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authent…
- CVE-2026-23822MEDIUMCVSS 5.3EG 5.32026-05-12
A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an attacker to cause excessive resource consu…
- CVE-2026-31248HIGHCVSS 7.5EG 7.52026-05-11
Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend extracts and validates XML files from .tar.gz archives using etree.fromstring() without disabling entity resolution. An attacker can cr…
- CVE-2026-40260MEDIUMCVSS 5.3EG 5.32026-04-17
pypdf is a free and open-source pure-python PDF library. In versions prior to 6.10.0, manipulated XMP metadata entity declarations can exhaust RAM. An attacker who exploits this vulnerability can craft a PDF which leads to large memory usa…
- CVE-2026-42212HIGHCVSS 7.1EG 7.12026-05-08
SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, Opening a .gpp file in the SolidCAM Postprocessor IDE extension causes the language server t…
Map vulnerabilities like CWE-776 to your infrastructure
EchelonGraph correlates every CVE — across CWE-776 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →