Cyber Resilience

CWE · MITRE source

CWE-776Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

Abstraction: Base · CVEs in our corpus: 88

The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.

If the DTD contains a large number of nested or recursive entities, this can lead to explosive growth of data when parsed, causing a denial of service.

Last updated: 20 August 2026 13:14 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: partial · 1 mapping(s) from 1 framework(s): CAPEC 1 (partial)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A02:2025 Security Misconfiguration.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • ID.RA-01
  • PR.PS-01
  • PR.PS-06
  • SI-10 Information Input Validation
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2009-1955 8.07.50.52992009-06-08
CVE-2014-2228 7.89.80.03312020-02-19
CVE-2013-4335 7.79.80.02462020-02-07
CVE-2021-23926 7.69.10.06212021-01-14
CVE-2022-23640 7.59.80.01272022-03-02
CVE-2019-19144 7.49.80.00712025-08-01
CVE-2019-11253 7.37.50.25942019-10-17
CVE-2017-18640 7.37.50.26722019-12-12
CVE-2020-24590 7.19.10.01262020-08-21
CVE-2019-15903 6.67.50.06642019-09-04
CVE-2019-12401 6.67.50.07442019-09-10
CVE-2019-5427 6.57.50.04882019-04-22
CVE-2022-0217 6.57.50.04652022-08-26
CVE-2011-1755 6.47.50.03662011-06-21
CVE-2021-32623 6.48.10.01252021-06-16
CVE-2015-9541 6.37.50.02492020-01-24
CVE-2019-20104 6.37.50.02432020-02-06
CVE-2011-3288 6.27.50.01772011-10-06
CVE-2019-15160 6.27.50.01672019-08-19
CVE-2012-6685 6.27.50.02172020-02-19
CVE-2022-26662 6.27.50.01962022-03-10
CVE-2022-33977 6.27.50.01722022-07-26
CVE-2022-25857 6.27.50.02202022-08-30
CVE-2024-28757 6.27.50.02012024-03-10
CVE-2026-26171 6.27.50.01752026-04-14