Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 20 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.0. Attackers can craft malicious XML metadata in media files to disclose local files, perform server-side request forgery, or cause denial of service through entity expansion. | |
| Title | getID3 through 1.9.26 XML External Entity Injection via XML2array | |
| First Time appeared |
Getid3
Getid3 getid3 |
|
| Weaknesses | CWE-611 | |
| CPEs | cpe:2.3:a:getid3:getid3:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Getid3
Getid3 getid3 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-20T11:09:41.588Z
Reserved: 2026-09-20T10:56:44.077Z
Link: CVE-2026-94108
No data.
Status : Received
Published: 2026-09-20T12:17:06.427
Modified: 2026-09-20T12:17:06.427
Link: CVE-2026-94108
No data.
OpenCVE Enrichment
Updated: 2026-09-20T12:30:17Z
