Cyber Posture

CWE · MITRE source

CWE-776Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

Abstraction: Base · CVEs in our corpus: 71

The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.

If the DTD contains a large number of nested or recursive entities, this can lead to explosive growth of data when parsed, causing a denial of service.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (0)AI

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2019-112536.57.50.83792019-10-17
CVE-2019-124013.57.50.32772019-09-10
CVE-2023-384902.56.80.19402023-07-27
CVE-2013-43352.19.80.02102020-02-07
CVE-2014-22282.19.80.02762020-02-19
CVE-2011-17552.07.50.08462011-06-21
CVE-2022-236402.09.80.00352022-03-02
CVE-2019-191442.09.80.00052025-08-01
CVE-2020-245901.99.10.00562020-08-21
CVE-2019-54271.87.50.04722019-04-22
CVE-2021-239261.89.10.00442021-01-14
CVE-2022-266621.87.50.05582022-03-10
CVE-2017-186401.77.50.02772019-12-12
CVE-2009-19551.67.50.02332009-06-08
CVE-2019-201041.67.50.02432020-02-06
CVE-2018-108681.67.50.01172021-05-26
CVE-2021-326231.68.10.00312021-06-16
CVE-2022-339771.67.50.02132022-07-26
CVE-2022-258571.67.50.00872022-08-30
CVE-2024-287571.67.50.01202024-03-10
CVE-2011-32881.57.50.00532011-10-06
CVE-2019-54421.57.50.00332019-06-12
CVE-2019-151601.57.50.00332019-08-19
CVE-2019-159031.57.50.00202019-09-04
CVE-2013-64601.56.50.02522019-11-05