getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.0. Attackers can craft malicious XML metadata in media files to disclose local files, perform server-side request forgery, or cause denial of service through entity expansion.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 20 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.0. Attackers can craft malicious XML metadata in media files to disclose local files, perform server-side request forgery, or cause denial of service through entity expansion. | |
| Title | getID3 through 1.9.26 XML External Entity Injection via XML2array | |
| First Time appeared |
Getid3
Getid3 getid3 |
|
| Weaknesses | CWE-611 | |
| CPEs | cpe:2.3:a:getid3:getid3:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Getid3
Getid3 getid3 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-20T11:09:41.588Z
Reserved: 2026-09-20T10:56:44.077Z
Link: CVE-2026-94108
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses