Common Weakness Enumeration
CWE Definition / CWE-827
CWE-827: Improper Control of Document Type Definition
The product does not restrict a reference to a Document Type Definition (DTD) to the intended control sphere. This might allow attackers to reference arbitrary DTDs, possibly causing the product to expose files, consume excessive system resources, or execute arbitrary http requests on behalf of the attacker.
Published:25 Oct 2010
Organization:MITRE
Modified:11 Dec 2025
