CWE-776: XML Entity Expansion
Improper Restriction of Recursive Entity References in DTDs
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
How it's found
XML Entity Expansion is typically found by tracing untrusted input from where it enters the system to the point where it is used without the check or neutralization this weakness describes, combining manual code review with dynamic testing.
If the DTD contains a large number of nested or recursive entities, this can lead to explosive growth of data when parsed, causing a denial of service.
Consequences
- DoS: Resource Consumption (Other): If parsed, recursive entity references allow the attacker to expand data exponentially, quickly consuming all system resources.
Mitigations
- Operation: If possible, prohibit the use of DTDs or use an XML parser that limits the expansion of recursive DTD entities.
- Implementation: Before parsing XML files with associated DTDs, scan for recursive entity declarations and do not continue parsing potentially explosive content.
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Frequently asked questions
What is CWE-776?
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
How do you find XML Entity Expansion?
XML Entity Expansion is typically found by tracing untrusted input from where it enters the system to the point where it is used without the check or neutralization this weakness describes, combining manual code review with dynamic testing.
What is the impact of CWE-776?
DoS: Resource Consumption (Other): If parsed, recursive entity references allow the attacker to expand data exponentially, quickly consuming all system resources.
Does TurboPentest test for XML Entity Expansion?
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Related CWEs
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a $99 pentest