XML External Entity (xee) Attack - Vulnerability

Threat entity extracted from intelligence sources

Frequency
10
occurrences
First Seen
November 24, 2025
Last Seen
December 2, 2025

XML External Entity (XEE) Attack is a vulnerability where an XML parser processes external entity declarations, enabling attackers to access local files, perform server-side requests, or cause other unintended actions.

XML External Entity (xee) Attack is a vulnerability tracked across 2 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed November 24, 2025; most recent activity December 2, 2025.

Overview

XML External Entity (XEE) Attack is a vulnerability where an XML parser processes external entity declarations, enabling attackers to access local files, perform server-side requests, or cause other unintended actions. In the Ubuntu/OpenJDK ecosystem, multiple advisories across OpenJDK versions (8, 17, 21, 25) and CRaC JDK builds have patched XEE flaws, underscoring its ongoing significance for Java-based deployments and containers.

Related Threat Clusters

Recent Intelligence Reports

  • Ubuntu 25.10 OpenJDK Critical Security Risks USN-7900-1 CVE-2025 — Linuxsecurity · December 2, 2025
  • Ubuntu 25.10: CRaC JDK 25 Important XML External Entity Advisory 2025 — Linuxsecurity · December 2, 2025
  • Ubuntu 25.10: Crucial Security Fix for OpenJDK 21 USN-7901-1 CVE-2025 — Linuxsecurity · December 2, 2025
  • USN-7902-1: CRaC JDK 25 vulnerabilities — Ubuntu · December 1, 2025
  • USN-7901-1: CRaC JDK 21 vulnerabilities — Ubuntu · December 1, 2025
  • USN-7900-1: CRaC JDK 17 vulnerabilities — Ubuntu · December 1, 2025
  • Ubuntu 25.10: OpenJDK 8 Critical XML External Entity Attack USN-7881 — Linuxsecurity · November 25, 2025
  • Ubuntu 25.10: OpenJDK 17 Critical Security Flaws USN-7883 — Linuxsecurity · November 25, 2025

Frequently asked questions

What is XML External Entity (xee) Attack?

XML External Entity (XEE) Attack is a vulnerability where an XML parser processes external entity declarations, enabling attackers to access local files, perform server-side requests, or cause other unintended actions.

Is XML External Entity (xee) Attack still active?

The most recent intelligence report mentioning XML External Entity (xee) Attack on ThreatCluster is dated December 2, 2025. Activity was first observed November 24, 2025, giving a tracked span from then to December 2, 2025.

What is XML External Entity (xee) Attack associated with?

Across ThreatCluster reporting, XML External Entity (xee) Attack most frequently co-occurs with Data Breach, Zero-day Exploit, Ubuntu, CVE-2025-53057, CVE-2025-53066, among 12 tracked related entities.

What are the latest developments involving XML External Entity (xee) Attack?

The most significant recent cluster is “Multiple OpenJDK Vulnerabilities Discovered in Ubuntu 25.10 and Derivatives” (11 articles · Updated December 2, 2025). XML External Entity (xee) Attack appears across 2 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on XML External Entity (xee) Attack?

XML External Entity (xee) Attack appears in 10 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown