Repository navigation
v1.3.0
This release hardens XmlToJsonConverter against entity-based denial of service and fixes two data-correctness issues in JsonToXmlConverter. Please read "Behavior changes" before upgrading: some inputs that were previously accepted are now rejected.
Behavior changes
XmlToJsonConverternow rejects references to entities declared in the DOCTYPE, both in attribute values and in element content, by throwing anInvalidArgumentException(exit code3from the CLI). Predefined entities (&,<,>,",') and character references (A) are unaffected.- In attribute values, reading the value expanded the entity with quadratic cost, which neither
loadXML()nor libxml2's own limits prevented. On libxml2 2.10.4, 16 MB of expanded content took about 14 s, and a crafted document of ~250 KB did not finish within a 15 s test timeout. - In element content, such references used to be silently dropped, losing data.
- If you rely on custom entities, inline them before passing the XML to the library.
- In attribute values, reading the value expanded the entity with quadratic cost, which neither
- JSON integers beyond the int64 range are now written in full. They are decoded as strings (
JSON_BIGINT_AS_STRING) instead of being rounded to a float, so12345678901234567890is no longer emitted as1.2345678901235E+19. - Characters that are not allowed in XML 1.0 are now rejected.
JsonToXmlConverterthrows anInvalidArgumentExceptionfor values containing control characters other than tab, line feed and carriage return, instead of silently producing a malformed document.
Added
- Regression tests for entity-expansion attacks (Billion Laughs, recursive entities, quadratic blowup in element content and in attribute values). The heavy payloads run in a separate PHP process with a reduced
memory_limitand a timeout, so a regression cannot crash or hang the test suite. - Tests for resource budgets on large documents, nesting depth limits in both directions, namespace handling in XML → JSON, markup and namespace injection through JSON keys and values, and additional file and temporary-file error cases.
Documentation
SECURITY.mdnow documents what the tests do and do not guarantee, the dependency on the libxml2 version bundled with PHP, and the library's limits: no size or time limits of its own, file paths are not validated, and namespaces are not preserved in XML → JSON.README.mddocuments the new behavior for entities, large integers and invalid characters.
Notes
- Entity-expansion protection relies on libxml2's built-in limits, which the library leaves enabled (it never passes
LIBXML_NOENTorLIBXML_PARSEHUGE). Results were verified on libxml2 2.10.4; other versions may behave differently, so running the test suite on your target environment is recommended. - For fully untrusted input, add your own size cap and execution timeout.
Full changelog: v1.2.0...v1.3.0