CVE Vulnerabilities

CVE-2024-40896

Improper Restriction of XML External Entity Reference

Published: Dec 23, 2024 | Modified: Nov 25, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
9.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting checked). This makes classic XXE attacks possible.

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

NameVendorStart VersionEnd Version
Libxml2Xmlsoft2.11.0 (including)2.11.9 (excluding)
Libxml2Xmlsoft2.12.0 (including)2.12.9 (excluding)
Libxml2Xmlsoft2.13.0 (including)2.13.3 (excluding)
Red Hat Enterprise Linux 10RedHatlibxml2-0:2.12.5-5.el10_0*
Libxml2Ubuntuoracular*
Libxml2Ubuntuupstream*

Potential Mitigations

References