Skip to content

v1.3.0

Choose a tag to compare

@A35G A35G released this 03 Oct 23:15
· 10 commits to main since this release

This release hardens XmlToJsonConverter against entity-based denial of service and fixes two data-correctness issues in JsonToXmlConverter. Please read "Behavior changes" before upgrading: some inputs that were previously accepted are now rejected.

Behavior changes

  • XmlToJsonConverter now rejects references to entities declared in the DOCTYPE, both in attribute values and in element content, by throwing an InvalidArgumentException (exit code 3 from the CLI). Predefined entities (&, <, >, ", ') and character references (A) are unaffected.
    • In attribute values, reading the value expanded the entity with quadratic cost, which neither loadXML() nor libxml2's own limits prevented. On libxml2 2.10.4, 16 MB of expanded content took about 14 s, and a crafted document of ~250 KB did not finish within a 15 s test timeout.
    • In element content, such references used to be silently dropped, losing data.
    • If you rely on custom entities, inline them before passing the XML to the library.
  • JSON integers beyond the int64 range are now written in full. They are decoded as strings (JSON_BIGINT_AS_STRING) instead of being rounded to a float, so 12345678901234567890 is no longer emitted as 1.2345678901235E+19.
  • Characters that are not allowed in XML 1.0 are now rejected. JsonToXmlConverter throws an InvalidArgumentException for values containing control characters other than tab, line feed and carriage return, instead of silently producing a malformed document.

Added

  • Regression tests for entity-expansion attacks (Billion Laughs, recursive entities, quadratic blowup in element content and in attribute values). The heavy payloads run in a separate PHP process with a reduced memory_limit and a timeout, so a regression cannot crash or hang the test suite.
  • Tests for resource budgets on large documents, nesting depth limits in both directions, namespace handling in XML → JSON, markup and namespace injection through JSON keys and values, and additional file and temporary-file error cases.

Documentation

  • SECURITY.md now documents what the tests do and do not guarantee, the dependency on the libxml2 version bundled with PHP, and the library's limits: no size or time limits of its own, file paths are not validated, and namespaces are not preserved in XML → JSON.
  • README.md documents the new behavior for entities, large integers and invalid characters.

Notes

  • Entity-expansion protection relies on libxml2's built-in limits, which the library leaves enabled (it never passes LIBXML_NOENT or LIBXML_PARSEHUGE). Results were verified on libxml2 2.10.4; other versions may behave differently, so running the test suite on your target environment is recommended.
  • For fully untrusted input, add your own size cap and execution timeout.

Full changelog: v1.2.0...v1.3.0