CVE-2024-28757

ADVISORY - nist

Summary

libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

EPSS Score: 0.00044 (0.112)

Common Weakness Enumeration (CWE)

ADVISORY - nist
ADVISORY - redhat

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in