CWE-776

Overview
  • CWE ID
  • 776
  • CWE Name
  • Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
  • CWE Abstraction
  • Base
  • CWE structure
  • Simple
  • CWE Status
  • Draft
Description
The software uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
Extended Description
If the DTD contains a large number of nested or recursive entities, this can lead to explosive growth of data when parsed, causing a denial of service.
Related CWEs
CWE ID View ID Nature Ordinal
674 1000 ChildOf Primary
674 1003 ChildOf Primary
409 1000 ChildOf