CVE-2023-34411: XML Library Project XML Library
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
The xml-rs crate before 0.8.14 for Rust and Crab allows a denial of service (panic) via an invalid <! token (such as <!DOCTYPEs/%<!A nesting) in an XML document. The earliest affected version is 0.8.9.
Affected products
- XML Library Project XML Library: before 0.8.14 (fixed in 0.8.14)
Published 2023-06-05. Last modified 2026-06-17.