CWE-776
Overview
- CWE ID
- 776
- CWE Name
- Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
- CWE Abstraction
- Base
- CWE structure
- Simple
- CWE Status
- Draft
Description
The software uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
Extended Description
If the DTD contains a large number of nested or recursive entities, this can lead to explosive growth of data when parsed, causing a denial of service.