XML External Entities (XXE)

XML external entities in C#

Description

Allowing DTD processing and external resource resolution for untrusted XML can let external entities read local files or trigger server-side requests. Setting DtdProcessing.Parse alone does not always allow external access; the XmlResolver configuration also matters.

Potential impact

  • Local file disclosure, requests to internal networks, and denial of service.

Remediation

Prohibit DTD processing and set XmlResolver to null.

Examples

Before

csharp
var settings = new XmlReaderSettings {
    DtdProcessing = DtdProcessing.Parse,
    XmlResolver = new XmlUrlResolver()
};

After

csharp
var settings = new XmlReaderSettings {
    DtdProcessing = DtdProcessing.Prohibit,
    XmlResolver = null
};

Explanation:

  • Before: A parser that permits external entities can expose local files or trigger server-side requests.
  • After: Disable DTD processing and set XmlResolver to null before parsing untrusted XML.

References