CWE-776: Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

BaseDraftExploit Likelihood: Medium

The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.

View on MITRE
Back to CWE Lookup

Extended Description

If the DTD contains a large number of nested or recursive entities, this can lead to explosive growth of data when parsed, causing a denial of service.

Technical Details

Structure
Simple

Applicable To

Languages
XML
Platforms

Learn More