Skip to main content
HIGH

CVE-2022-0217

CVSS v3

7.5

HIGH

EPSS Score

5.4 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in expansion of recursive entity references from DTDs (CWE-776). In addition, depending on the libexpat version used, it may also allow injections using XML External Entity References (CWE-611).

Technical details

Published
2022-08-26

Frequently asked questions

What is CVE-2022-0217?

It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in expansion of recursive entity references from DTDs (CWE-776). In addition, depending on the libexpat version used, it may also allow injections using XML External Entity References (CWE-611).

Is CVE-2022-0217 actively exploited?

Active exploitation of CVE-2022-0217 has not been confirmed. Its EPSS score was 5.4% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-0217?

CVE-2022-0217 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2022-0217 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key