CVE-2024-40896

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Dec 23, 2024
Updated: Feb 28, 2025
CWE ID 611

Summary

CVE-2024-40896 is a vulnerability affecting libxml2 versions prior to 2.11.9, 2.12.9, and 2.13.3. Despite efforts by custom SAX handlers to prevent it, the SAX parser in these versions can still generate events for external entities. This issue opens the door to Classic XML External Entity (XXE) attacks, putting systems using these libxml2 versions at risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share