CWE-6111 advisories

XML External Entity (XXE)

What it is

An XML parser resolves external entities, letting an attacker read files or reach internal services.

How to fix it

Upgrade and disable DTD/external-entity processing in the parser.

How to avoid it

Disable external entities and DTDs on every XML parser by default.

Known XML External Entity (XXE) vulnerabilities

Stateward flags XML External Entity (XXE) in your own code and dependencies on every pull request.

Scan my repo

Summarize with AI

ChatGPTClaudePerplexity

Sources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.