CVE-2026-45071 is an XML External Entity (XXE) vulnerability in Symfony's DomCrawler component. In affected versions prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Crawler::addXmlContent() sets DOMDocument::$validateOnParse to true before invoking loadXML(). This behavior re-enables external entity processing during XML parsing, allowing attacker-controlled XML input to define and expand external entities. As a result, XML content supplied to addXmlContent() can reference local resources through external entities and cause the parser to disclose local file contents.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This 45-file repository is a static XML fixture collection, not an executable exploit client. README.md identifies it as zk-xml-probe for authorized testing of XML parser behavior associated with CVE-2026-45071. Most files are deliberately varied XML/HTML-shaped inputs intended for ingestion by an XML parser or an application extracting title, meta-description, and Open Graph metadata. Control and baseline fixtures (ctl.xml, noent.xml, f1.xml, g1.xml, r0.xml, r9.xml, t0.xml, t2.xml, v0.xml, vN.xml, and w0.xml) help identify normal parsing and entity/error handling. XXE fixtures place entity references in metadata attributes, titles, text/body nodes, and DTD declarations. They test local-file reads, Linux process-environment disclosure, PHP-specific stream wrappers, retrieval of a remote DTD, and optional expect-wrapper command execution. ext.dtd is the remote-DTD payload and defines a recognizable marker entity. Exploitation requires a separate delivery mechanism that submits one of these XML documents to a vulnerable parser; no network client, shell script, or automation is included.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.