CVE-2016-9180

CRITICAL

XML::Twig for Perl - XML External Entity Injection via expand_external_ents Option Bypass

Title source: llm
STIX 2.1

Description

perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/94219
Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/11/04/2

Scores

CVSS v3 9.1
EPSS 0.0354
EPSS Percentile 87.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Details

CWE
CWE-611
Status published
Products (1)
xmltwig/xml-twig_for_perl
Published Dec 22, 2016
Tracked Since Feb 18, 2026