Glossary
XXE (XML external entity)
An XML document that makes the parser fetch a file or a URL.
XML allows a document to define entities, including external ones that reference a file path or a URL. A parser that resolves them can be made to read /etc/passwd, or to make a request to an internal address the attacker cannot reach directly, simply by parsing a hostile document.
A related attack needs no external reference at all. A set of nested internal entities, each expanding to several copies of the next, can expand a few hundred bytes into gigabytes, the "billion laughs" attack, exhausting memory.
Both are prevented the same way: do not resolve external entities, and cap expansion. A parser configured that way handles ordinary XML correctly while treating entity definitions as data rather than instructions.