← Back to browse · API

CVE-2017-7375

Severity
CRITICAL
CVSS
9.8
EPSS
0.02591
Risk score
40.11
CISA KEV
No
PoC
No
Published
2018-02-19
Modified
2025-12-03
First seen
2026-08-07
Aliases
EUVD-2017-16402, GHSA-WW2P-X466-VPWF
Products
n/a:n/a n/a
Sources
euvd EUVD-2017-16402

Description

A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a higher-risk attack surface in libxml2 not usually reachable with default parser flags, and expose content from local files, HTTP, or FTP servers (which might be otherwise unreachable).

References