xxe
Safeguard articles tagged "xxe" — guides, analysis, and best practices for software supply chain and application security.
18 articles
XXE Fix in Java: How to Harden Every XML Parser
The XXE fix in Java is the same idea across every parser — turn off DOCTYPE and external entities before you feed it untrusted XML. Here are the exact settings for each JDK XML API.
Choosing an npm XML Parser: Security Comparison and XXE Pitfalls
Not every npm XML parser carries the same risk. We compare xml2js, fast-xml-parser, sax, and libxmljs on their CVE history, XXE exposure, and safe configuration.
How to Use PyPI openpyxl Safely: Security Risks and Fixes
The openpyxl package on PyPI is safe for most workloads, but XML parsing and spreadsheet formula injection deserve attention. Here is what to watch for.
XXE Attack Demo: Understanding and Defending Against XML External Entities
An XXE attack demo makes the vulnerability click: an XML parser that trusts external entities can be tricked into reading files or making requests. Here is how it works and how to shut it down.
xercesImpl: XXE Risks in Java XML Parsing and How to Configure It
The xercesImpl Maven artifact turns up transitively in thousands of Java builds. Here is its real CVE history, why XXE is your configuration's fault, and the hardening block to paste.
XML External Entity (XXE) Prevention: Disabling the Features That Attack You
XXE attacks exploit XML parser features that most applications never need. Here is how to disable them across every major language and framework.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.