CVE-2026-94108

MEDIUMCVSS 6.5/10

Last modified

CVE-2026-94108 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.0. Attackers can craft malicious XML metadata in media files to disclose local files, perform server-side request forgery, or cause denial of service through entity expansion..

Description

getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.0. Attackers can craft malicious XML metadata in media files to disclose local files, perform server-side request forgery, or cause denial of service through entity expansion.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
james-heinrichgetid3<= 1.9.26

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-94108?
getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.0. Attackers can craft malicious XML metadata in media files to disclose local files, perform server-side request forgery, or cause denial of service through entity expansion.
How severe is CVE-2026-94108?
CVE-2026-94108 has a CVSS score of 6.5/10 (MEDIUM severity).
How do I fix CVE-2026-94108?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-94108?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST