Description
If an XML parser loads external entities or DTDs, an attacker may cause it to read local files or access internal network resources.
Potential impact
- File disclosure, SSRF, or denial of service may result.
Remediation
Disable external entity expansion and external DTD loading. In libxml2 2.13.0 and later, XML_PARSE_NO_XXE blocks external DTDs and entities. Also prevent custom resource loaders from allowing untrusted external access.
Examples
Before
c
xmlReadMemory(buf, size, NULL, NULL, XML_PARSE_NOENT | XML_PARSE_DTDLOAD);
After
c
xmlReadMemory(buf, size, NULL, NULL, XML_PARSE_NONET);
Explanation:
- Before: External entity expansion and DTD loading are enabled.
- After: The
XML_PARSE_NOENTandXML_PARSE_DTDLOADflags are removed.XML_PARSE_NONETalone does not block local files. Since libxml2 2.15 has no built-in network client, custom loaders must handle that option.