/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2024-40896

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-40896

Severity

9.1

Critical

CVSS V3

Description

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing