Common Weakness Enumeration

    CWE Definition / CWE-611

    CWE-611: Improper Restriction of XML External Entity Reference

    The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

    Published:7 May 2007
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-610: Externally Controlled Reference to a Resource in Another Sphere

    CWE-610: Externally Controlled Reference to a Resource in Another Sphere

    CWE-441: Unintended Proxy or Intermediary ('Confused Deputy')