Skip to content

Latest commit

 

History

History
3 lines (2 loc) · 246 Bytes

avoid_entity_expansion.md

File metadata and controls

3 lines (2 loc) · 246 Bytes

Avoid entity expansion

Many XML parsers support entity expansion, this is however a security issue, the issue is called XML BOMB since you can get a XML parser to do recursive expansion of entities, letting the XML parser hug all resources.