Weaknesses of type CWE-611

648 results

Processamento inseguro de XML externo (XXE)

Ocorre quando uma aplicação processa XML sem desabilitar a resolução de entidades externas, permitindo que um atacante injete referências a arquivos locais ou recursos remotos. O parser XML carrega esses recursos e expõe seu conteúdo ou causa negação de serviço, comprometendo confidencialidade e disponibilidade.

Example

Um endpoint de API aceita XML do usuário e o processa com um parser padrão. Um atacante envia um payload XXE que referencia `/etc/passwd` via entity declaration, e o parser retorna o conteúdo do arquivo na resposta ou em logs. Alternativa: bomb XML que incha exponencialmente, travando o servidor.

How to mitigate

Desabilite explicitamente entidades externas e DTDs no parser XML (ex: `XMLConstants.FEATURE_SECURE_PROCESSING` em Java; `LIBXML_DISABLE_ENTITY_LOADER` em PHP). Valide e sanitize entrada XML; prefira JSON quando possível. Teste com payloads XXE conhecidos.

CVE-2025-12531HIGHIBM InfoSphere Information Server is affected by an XML external entity injection (XXE) vulnerabilityEPSS 0.7%CVE-2024-39726HIGHIBM Engineering Insights XML external entity injectionEPSS 0.7%CVE-2021-33950HIGHAn issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function.EPSS 0.7%CVE-2024-56322LOWGoCD vulnerable to XXE injection via abuse of unused XML configuration repository functionalityEPSS 0.7%CVE-2026-22016HIGHVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). EPSS 0.7%CVE-2024-4357MEDIUMXML External Entity Processing Information DisclosureEPSS 0.7%CVE-2022-43570HIGHXML External Entity Injection through a custom View in Splunk EnterpriseEPSS 0.7%CVE-2021-32972—Panasonic FPWIN Pro, all Versions 7.5.1.1 and prior, allows an attacker to craft a project file specifying a URI that causes the XML parser EPSS 0.7%CVE-2024-46603HIGHAn XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows attackers to cause a DeEPSS 0.7%CVE-2024-46602HIGHAn issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML External Entity (XXE) vulnerability may allEPSS 0.7%CVE-2021-43990MEDIUMICSA-22-109-03 FANUC ROBOGUIDE Simulation PlatformEPSS 0.7%CVE-2022-43689MEDIUMConcrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XXE based DNS requests leading to IP disclosure.EPSS 0.7%CVE-2023-41034MEDIUMDDFFileParser in eclipse leshan is vulnerable to XXE AttacksEPSS 0.7%CVE-2025-34490MEDIUMGFI MailEssentials < 21.8 XXE Arbitrary File ReadEPSS 0.7%CVE-2025-68280MEDIUMApache SIS: XML External Entity (XXE) vulnerabilityEPSS 0.7%CVE-2023-45192HIGHIBM Engineering Requirements Management DOORS Next XML external entity injectionEPSS 0.7%CVE-2023-22377HIGHImproper restriction of XML external entity reference (XXE) vulnerability exists in tsClinical Define.xml Generator all versions (v1.0.0 to EPSS 0.7%CVE-2023-42445MEDIUMPossible local file exfiltration by XML External entity injectionEPSS 0.7%CVE-2021-4311MEDIUMTalend Open Studio for MDM XML xml external entity referenceEPSS 0.7%CVE-2024-46985HIGHDataEase has an XXE vulnerabilityEPSS 0.7%