CWE-776
Medium likelihoodImproper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
Parent: CWE-674 - Uncontrolled Recursion
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
86 vulnerabilities with CWE-776
CVE-2026-14865
MEDIUM
XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAX
CVSS 5.3
CVE-2026-14979
MEDIUM
IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML Entity Expansion attack
CVSS 5.3
CVE-2026-45304
HIGH
Symfony: YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")
CVSS 7.5
CVE-2026-45133
HIGH
Symfony: [Yaml] Harden the parser when handling untrusted input
CVSS 7.5
CVE-2026-44018
MEDIUM
Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
CVSS 5.5
CVE-2026-12993
MEDIUM
Apicurio/apicurio-registry: apicurio-registry: xml entity-expansion denial of service via internal dtd subset
CVSS 6.5
CVE-2026-44020
HIGH
Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
CVSS 7.5
CVE-2026-45771
HIGH
Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion
CVSS 7.5
CVE-2026-23822
MEDIUM
HPE ArubaOS AOS-8 Instant - XML External Entity Denial of Service
CVSS 5.3
CVE-2026-31248
HIGH
Docling < 2.61.0 - XML Entity Expansion Denial of Service via METS GBS Backend
CVSS 7.5
CVE-2026-42212
HIGH
SolidCAM-GPPL-IDE: XML External Entity (XXE) and billion-laughs DoS in VMID parser
CVE-2026-41673
HIGH
xmldom: Denial of service via uncontrolled recursion in XML serialization
CVSS 7.5
CVE-2026-40260
MEDIUM
pypdf: Manipulated XMP metadata entity declarations can exhaust RAM
CVSS 5.3
CVE-2026-33116
HIGH
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVSS 7.5
CVE-2026-26171
HIGH
Microsoft .NET and PowerShell - Resource Consumption Denial of Service
CVSS 7.5
CVE-2026-33908
HIGH
ImageMagick is vulnerable to Stack Overflow in DestroyXMLTree()
CVSS 7.5
CVE-2026-33036
HIGH
fast-xml-parser <5.5.6 - Numeric Entity Expansion Denial of Service
CVSS 7.5
CVE-2026-29074
HIGH
SVGO 2.1.0-2.8.0/3.0.0-3.3.2/4.0.0 - DoS
CVSS 7.5
CVE-2026-27807
MEDIUM
Markus < 2.9.4 - XML External Entity Injection via YAML Alias Parsing
CVSS 4.9
CVE-2026-26278
HIGH
fast-xml-parser 4.1.3-5.3.5 - XML External Entity Injection via Unrestricted Entity Expansion
CVSS 7.5
CVE-2025-20369
MEDIUM
Splunk <9.4.4, <9.3.6, <9.2.8 - DoS
CVSS 4.6
CVE-2025-5466
MEDIUM
Ivanti Connect Secure < 22.7 - Authenticated Denial of Service via XML Entity Expansion
CVSS 4.9
CVE-2025-3225
HIGH
run-llama/llama_index <v0.12.21 - DoS
CVSS 7.5
CVE-2025-0617
MEDIUM
Trellix HX Console < 5.1.1 - Denial of Service via XML Entity Expansion
CVSS 5.9
CVE-2024-43398
MEDIUM
REXML < 3.3.6 - Denial of Service via Deep XML Element Parsing
CVSS 5.9
Details
Vulnerabilities
86
Exploit Likelihood
Medium