CWE-827Variant

Improper Control of Document Type Definition

Incomplete in the CWE catalog · 3 CVEs mapped

3
CVEs mapped
6.8
Median CVSS
What it is

The product does not restrict a reference to a Document Type Definition (DTD) to the intended control sphere. This might allow attackers to reference arbitrary DTDs, possibly causing the product to expose files, consume excessive system resources, or execute arbitrary http requests on behalf of the attacker.

Recent examples
none
CVE-2026-15803

CVE-2026-15803 - UNKNOWN Severity Vulnerability

In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF data or query results, permitting DOCTYPE declarations, external entity references, and external DTD loading. This is due to an incomplete fix for CVE-2018-1000644: the earlier fix did not cover all parser entry points. The issue is resolved in RDF4J 5.3.2, which rejects or disables DOCTYPE declarations, external entities, and external DTD loading by default.

no explanation yet
0%
epss
6.8cvss
CVE-2025-4949

XXE vulnerability in Eclipse JGit

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.

MEDIUMno explanation yet
1%
epss
4.6cvss
CVE-2024-9044

XML External Entity (XXE) Vulnerability in EasyTax

A XML External Entity (XXE) vulnerability has been identified in Easy Tax Client Software 2023 1.2 and earlier across multiple platforms, including Windows, Linux, and macOS.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-827
Abstraction
Variant
Structure
Simple
Status
Incomplete
References (1)