In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2...
        
  Critical severity
        
          Unreviewed
      
        Published
          Dec 23, 2024 
          to the GitHub Advisory Database
          •
          Updated Feb 28, 2025 
      
  
Description
        Published by the National Vulnerability Database
      Dec 23, 2024 
    
  
        Published to the GitHub Advisory Database
      Dec 23, 2024 
    
  
        Last updated
      Feb 28, 2025 
    
  
In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.
References