XML external entities (XXE)

XML external entities (XXE)

Description

If an XML parser loads external entities or DTDs, an attacker may cause it to read local files or access internal network resources.

Potential impact

  • File disclosure, SSRF, or denial of service may result.

Remediation

Disable external entity expansion and external DTD loading. In libxml2 2.13.0 and later, XML_PARSE_NO_XXE blocks external DTDs and entities. Also prevent custom resource loaders from allowing untrusted external access.

Examples

Before

c
xmlReadMemory(buf, size, NULL, NULL, XML_PARSE_NOENT | XML_PARSE_DTDLOAD);

After

c
xmlReadMemory(buf, size, NULL, NULL, XML_PARSE_NONET);

Explanation:

  • Before: External entity expansion and DTD loading are enabled.
  • After: The XML_PARSE_NOENT and XML_PARSE_DTDLOAD flags are removed. XML_PARSE_NONET alone does not block local files. Since libxml2 2.15 has no built-in network client, custom loaders must handle that option.

References