CVE Vulnerabilities

CVE-2024-40896

Improper Restriction of XML External Entity Reference

Published: Dec 23, 2024 | Modified: Nov 25, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
9.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Ubuntu
MEDIUM

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting checked). This makes classic XXE attacks possible.

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

Name Vendor Start Version End Version
Libxml2 Xmlsoft 2.11.0 (including) 2.11.9 (excluding)
Libxml2 Xmlsoft 2.12.0 (including) 2.12.9 (excluding)
Libxml2 Xmlsoft 2.13.0 (including) 2.13.3 (excluding)
Red Hat Enterprise Linux 10 RedHat libxml2-0:2.12.5-5.el10_0 *
Libxml2 Ubuntu oracular *
Libxml2 Ubuntu upstream *

Potential Mitigations

References