CWE-827: Improper Control of Document Type Definition
The product does not restrict a reference to a Document Type Definition (DTD) to the intended control sphere. This might allow attackers to reference arbitrary DTDs, possibly causing the product to expose files, consume excessive system resources, or execute arbitrary http requests on behalf of the attacker.
3 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-15803 — In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsin
- CVE-2025-4949 — XXE vulnerability in Eclipse JGit
- CVE-2024-9044 — XML External Entity (XXE) Vulnerability in EasyTax
Recently published
- CVE-2026-15803 — In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsin
- CVE-2025-4949 — XXE vulnerability in Eclipse JGit
- CVE-2024-9044 — XML External Entity (XXE) Vulnerability in EasyTax