PT-2022-11601 · Unknown+1 · Xml-Conduit+1

·

CVE-2021-4249

·

Published

2022-12-18

·

Updated

2026-06-22

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions xml-conduit versions prior to 1.9.1.0
Description A vulnerability was found in the DOCTYPE Entity Expansion Handler component of xml-conduit, affecting an unknown function of the file xml-conduit/src/Text/XML/Stream/Parse.hs. The manipulation leads to an infinite loop and can be launched remotely.
Recommendations For versions prior to 1.9.1.0, upgrade to version 1.9.1.0 to address this issue. As a temporary workaround, consider restricting the use of the DOCTYPE Entity Expansion Handler component until the upgrade is applied.

Fix

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-4249
HSEC-2023-0004
OPENSUSE-SU-2026:11086-1

Affected Products

Debian
Xml-Conduit