Bio-Formats has an XML External Entity (XXE) vulnerability
Moderate severity
GitHub Reviewed
Published
Jan 7, 2026
to the GitHub Advisory Database
•
Updated Jan 8, 2026
Description
Published by the National Vulnerability Database
Jan 7, 2026
Published to the GitHub Advisory Database
Jan 7, 2026
Last updated
Jan 8, 2026
Reviewed
Jan 8, 2026
Bio-Formats versions up to and including 8.3.0 contain an XML External Entity (XXE) vulnerability in the Leica Microsystems metadata parsing component (e.g., XLEF). The parser uses an insecurely configured DocumentBuilderFactory when processing Leica XML-based metadata files, allowing external entity expansion and external DTD loading. A crafted metadata file can trigger outbound network requests (SSRF), access local system resources where readable, or cause a denial of service during XML parsing.
References