Glossary

XXE (XML external entity)

An XML document that makes the parser fetch a file or a URL.

XML allows a document to define entities, including external ones that reference a file path or a URL. A parser that resolves them can be made to read /etc/passwd, or to make a request to an internal address the attacker cannot reach directly, simply by parsing a hostile document.

A related attack needs no external reference at all. A set of nested internal entities, each expanding to several copies of the next, can expand a few hundred bytes into gigabytes, the "billion laughs" attack, exhausting memory.

Both are prevented the same way: do not resolve external entities, and cap expansion. A parser configured that way handles ordinary XML correctly while treating entity definitions as data rather than instructions.