Disabling External Entities in libxml By Default

From: Date: Wed, 29 Jul 2015 20:37:52 +0000
Subject: Disabling External Entities in libxml By Default
Groups: php.internals 
Request: Send a blank email to internals+get-87372@lists.php.net to get a copy of this message
All, I wanted to float an idea by you for PHP 7 (or 7.1 depending on the RM's feedback). Currently, PHP by default is vulnerable to XXE attacks: https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Processing To bypass this, you need to turn off external entity loading: libxml_disable_entity_loader(true); What I'm proposing is to disable entity loading by default. That way it requires developers to opt-in to actually load external entities. Thoughts? Anthony

« previous php.internals (#87372) next »