Core: XmlPullParser processes external DTD entities (XXE) — disable FEATURE_PROCESS_DOCDECL in Xml#createParser()

Open Beginner friendly
#2,179 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
84/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Quiet
Tech stack
java
Domain
security

Research direction

Start at Xml#createParser() in the google-http-client-xml module and inspect how the new XmlPullParser is configured. Run or add the named regression test, testCreateParser_disablesDocDecl, using the issue's DTD entity example. Done means document declarations are disabled or safely rejected, and the regression test confirms the entity is not resolved.

Written by the indexing model from the issue text.

Description

Environment details

  1. Core (XML) — Xml#createParser() in google-http-client-xml
  2. OS type and version: Any (JVM-level issue, not OS-specific)
  3. Java version: Any (Java 8+)
  4. google-http-client-xml version: 2.1.1 and earlier

Problem Statement

Xml#createParser() returns a raw XmlPullParser without disabling
XmlPullParser.FEATURE_PROCESS_DOCDECL. If an attacker can influence the XML content
parsed by the library (e.g. via a malicious server response or injected content), they can
embed a <!DOCTYPE> declaration with external entity references (),
causing the parser to resolve arbitrary external entities.

This is a classic XML External Entity (XXE) vulnerability.


Steps to reproduce

  1. Call Xml.createParser() and feed it XML containing an inline DTD with entity
    declarations ( ]>).
  2. Parse the document with Xml.parseElement(...).
  3. Observe that the entity &xxe; is resolved and its value appears in the parsed output
    instead of being rejected or left unexpanded.

Code example

XmlPullParser parser = Xml.createParser();
String xmlWithDtd = "\n"
+ "\n"
+ "]>\n"
+ "&xxe;";
parser.setInput(new StringReader(xmlWithDtd));

SimpleTypeString result = new SimpleTypeString();
Xml.parseElement(parser, result, new XmlNamespaceDictionary().set("", ""), null);
// result.value == "injected" <-- DTD entity resolved, XXE confirmed


Security Impact

  • Allows entity injection / content spoofing from malicious XML input.
  • In environments parsing untrusted XML (e.g. API responses from attacker-controlled
    servers), this could lead to information disclosure or server-side request forgery (SSRF)
    if external URI entities are supported by the underlying parser implementation.

Proposed Fix

Set FEATURE_PROCESS_DOCDECL to false immediately after creating the parser, with a
graceful fallback for parsers that do not support the feature flag:

public static XmlPullParser createParser() throws XmlPullParserException {
  XmlPullParser parser = getParserFactory().newPullParser();
  try {
    parser.setFeature(XmlPullParser.FEATURE_PROCESS_DOCDECL, false);
  } catch (XmlPullParserException e) {
    // Ignore if the feature is not supported by this parser implementation
  }
  return parser;
}

A regression test (testCreateParser_disablesDocDecl) is included in the accompanying PR
verifying that DTD entity content is not resolved (or that the parser throws, which is also
an acceptable safe outcome).

Dominant language
Java
Stars
1.4k
Forks
473
PR merge metrics
No merged PRs in 30d

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from googleapis/google-http-java-client

All issues in googleapis/google-http-java-client

Similar issues

More Java issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.