An XML parser resolves external entities, letting an attacker read files or reach internal services.
Upgrade and disable DTD/external-entity processing in the parser.
Disable external entities and DTDs on every XML parser by default.
Stateward flags XML External Entity (XXE) in your own code and dependencies on every pull request.
Scan my repoSources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.