Executive brief
NanoXML is a lightweight XML parsing library used by developers to parse and process XML documents in applications. By default, the library has XML external entity (XXE) support enabled, which can allow attackers to read arbitrary files, perform denial-of-service attacks, or conduct server-side request forgery (SSRF) if an application parses untrusted XML input without proper validation.
Technical details
The vulnerability is an XML External Entity (XXE) injection flaw in NanoXML's XML parser. The root cause is that external entity processing is enabled by default, allowing attackers to inject malicious XML entity definitions into input documents. An attacker can exploit this by submitting crafted XML containing external entity declarations that reference local files (e.g., /etc/passwd) or external URLs. No special authentication is required; the attack only requires the ability to submit XML to an application using the vulnerable NanoXML library. Successful exploitation can lead to arbitrary file disclosure, denial of service, or server-side request forgery. Mitigation involves disabling external entity processing in the NanoXML configuration.
Affected products
- NanoXML NanoXML 2.2.3
Timeline
- 2026-09-08: disclosed