CVE-2024-40896 Details
Description
In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.
A vulnerability allowing XML External Entity (XXE) attacks has been identified in libxml2 versions 2.11 prior to 2.11.9, 2.12 prior to 2.12.9, and 2.13 prior to 2.13.3. The issue arises in the SAX parser, which can generate events for external entities even when custom SAX handlers attempt to override entity content. This regression, introduced in libxml2 2.13, affects downstream projects like LibreOffice that rely on libxml2 for XML parsing. The vulnerability can be exploited by crafting a specific XML document that takes advantage of the SAX parser's handling of external entities.
Users can upgrade to libxml2 versions 2.11.9, 2.12.9 or 2.13.3 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 24, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.netapp.com/advisory/ntap-20250228-0004/ | CVE | Third Party Advisory |
| https://gitlab.gnome.org/GNOME/libxml2/-/commit/1a8932303969907f6572b1b6aac4081c56adb5c6 | [email protected] | Issue Tracking |
| https://gitlab.gnome.org/GNOME/libxml2/-/issues/761 | [email protected] | Issue Tracking |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| xmlsoft libxml2 | >= 2.11.0, < 2.11.9 >= 2.12.0, < 2.12.9 >= 2.13.0, < 2.13.3 |
CPE
Remediation
| |
| netapp hci compute node | All versions |
CPE
Remediation
| |
| netapp solidfire & hci management node | All versions |
CPE
Remediation
| |
| netapp solidfire & hci storage node | All versions |
CPE
Remediation
| |
| netapp h300s firmware | All versions |
CPE
Remediation
| |
| netapp h300s | All versions |
CPE
Remediation
| |
| netapp h410s firmware | All versions |
CPE
Remediation
| |
| netapp h410s | All versions |
CPE
Remediation
| |
| netapp h500s firmware | All versions |
CPE
Remediation
| |
| netapp h500s | All versions |
CPE
Remediation
| |
| netapp h700s firmware | All versions |
CPE
Remediation
| |
| netapp h700s | All versions |
CPE
Remediation
| |
| netapp h410c firmware | All versions |
CPE
Remediation
| |
| netapp h410c | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 25, 2025 | Initial Analysis | [email protected] |
| Feb 28, 2025 | CVE Modified | CVE |
| Dec 24, 2024 | CVE Modified | CISA-ADP |
| Dec 23, 2024 | CVE Modified | [email protected] |
| Dec 23, 2024 | New CVE Received | [email protected] |