Skip to content

Conversation

@hannob
Copy link
Contributor

@hannob hannob commented Nov 13, 2025

By default, Saxon allows access to external DTDs and both file and http urls, which enables XXE attacks.

This patch configures the Saxon processor used in the validation code to not support any external URLs (neither network nor files).

@arj03 arj03 merged commit 349a4bf into iterasdev:master Nov 13, 2025
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants