Vulnerability record · CVE-2022-0217 · published 26 August 2022
CVE-2022-0217: Prosody xml external entity (xxe) vulnerability
Prosody · Prosody
It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in expansion of recursive entity references from DTDs (CWE-776). In addition, depending on the libexpat version used, it may also allow injections using XML External Entity References (CWE-611).
Description
It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in expansion of recursive entity references from DTDs (CWE-776). In addition, depending on the libexpat version used, it may also allow injections using XML External Entity References (CWE-611).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=2040639 | Issue TrackingThird Party Advisory |
| https://prosody.im/security/advisory_20220113/ | ExploitPatchVendor Advisory |
| https://prosody.im/security/advisory_20220113/1.patch | PatchVendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2040639 | Issue TrackingThird Party Advisory |
| https://prosody.im/security/advisory_20220113/ | ExploitPatchVendor Advisory |
| https://prosody.im/security/advisory_20220113/1.patch | PatchVendor Advisory |
Track CVE-2022-0217 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-0217), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.