CWE-776
2 CVEs of this weakness class.
- CVE-2024-28757HIGH 7.5Real · low riskEPSS 2%
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
- CVE-2023-52426MED 5.5EPSS 0%
libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.