CVE-2016-9180: Xmltwig XML-Twig For Perl

Critical severity, CVSS 9.1. EPSS: 3.6% chance of exploitation in the next 30 days.

perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting.

Affected products

  • Xmltwig XML-Twig For Perl: affected versions not specified

Published 2016-12-22. Last modified 2026-06-17.