CWE-776: XML Entity Expansion
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
39 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-33036 — fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)
- CVE-2025-3225 — XML Entity Expansion vulnerability in run-llama/llama_index
- CVE-2026-78681 — NLTK before 3.10.3 Entity Expansion DoS via ElementTree
- CVE-2026-73569 — fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
- CVE-2026-45304 — Symfony: YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")
- CVE-2026-3415 — XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products Allows File Reading and Denial of Service
- CVE-2024-28982 — Hitachi Vantara Pentaho Business Analytics Server - Improper Restriction of XML External Entity Reference
- CVE-2026-45133 — Symfony: [Yaml] Harden the parser when handling untrusted input
- CVE-2026-26278 — fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)
- CVE-2026-44020 — Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
- CVE-2026-29074 — SVGO: DoS through entity expansion in DOCTYPE (Billion Laughs)
- CVE-2026-45771 — Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion
- CVE-2026-42212 — SolidCAM-GPPL-IDE: XML External Entity (XXE) and billion-laughs DoS in VMID parser
- CVE-2025-0617 — An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The
- CVE-2024-43398 — REXML denial of service vulnerability
- CVE-2024-27142 — Pre-authenticated XXE injection
- CVE-2024-27141 — Pre-authenticated Time-Based Blind XXE injection
- CVE-2024-1455 — Billion Laughs Attack leading to DoS in langchain-ai/langchain
- CVE-2026-40260 — pypdf: Manipulated XMP metadata entity declarations can exhaust RAM
- CVE-2026-12993 — Apicurio/apicurio-registry: apicurio-registry: xml entity-expansion denial of service via internal dtd subset
Recently published
- CVE-2026-58234 — Denial of Service vulnerability in SAP Process Integration (SOAP Adapter)
- CVE-2026-16180 — IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
- CVE-2026-78681 — NLTK before 3.10.3 Entity Expansion DoS via ElementTree
- CVE-2026-73569 — fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
- CVE-2026-3415 — XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products Allows File Reading and Denial of Service
- CVE-2026-14865 — XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAX
- CVE-2026-14979 — IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML Entity Expansion attack
- CVE-2026-45304 — Symfony: YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")
- CVE-2026-45133 — Symfony: [Yaml] Harden the parser when handling untrusted input
- CVE-2026-44018 — Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
- CVE-2026-12993 — Apicurio/apicurio-registry: apicurio-registry: xml entity-expansion denial of service via internal dtd subset
- CVE-2026-44020 — Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
- CVE-2026-45771 — Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion
- CVE-2026-42212 — SolidCAM-GPPL-IDE: XML External Entity (XXE) and billion-laughs DoS in VMID parser
- CVE-2026-40260 — pypdf: Manipulated XMP metadata entity declarations can exhaust RAM
- CVE-2026-33036 — fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)
- CVE-2026-29074 — SVGO: DoS through entity expansion in DOCTYPE (Billion Laughs)
- CVE-2026-27807 — MarkUs: YAML alias (‘billion laughs’) DoS in config upload
- CVE-2026-26278 — fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)
- CVE-2025-20369 — Extensible Markup Language (XML) External Entity Injection (XXE) through Dashboard label field on Splunk Enterprise