CVE-2026-94108: getID3 through 1.9.26 XML External Entity Injection via XML2array

Published Sep 20, 2026
·
Updated

getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before 8.0. Attackers can craft malicious XML metadata in media files to disclose local files, perform server-side request forgery, or cause denial of service through entity expansion.

Affected Software

2 affected components
getID3 getID3<=1.9.26
php<8.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade getID3 to a version that resolves this vulnerability.

    Fixed in 1.9.26
  2. Upgrade

    Upgrade getID3 to a version that resolves this vulnerability.

    Fixed in 8.0

Event History

Sep 20, 2026
CVE Published
via MITRE·11:09 AM
Data Sourced
via MITRE·11:09 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Deployments using getID3 through 1.9.26 on PHP versions before 8.0 are exposed when they process media files whose XML metadata can be attacker-controlled.

2

What does an attacker need to exploit this issue?

An attacker needs to craft a media file containing malicious XML metadata and have the affected application process it with the XML2array helper function. No authentication or user interaction is required according to the provided vector.

3

Are default configurations affected?

The issue is tied to PHP versions before 8.0 because entity loading is not properly disabled there. The provided data does not identify any additional configuration prerequisite beyond processing malicious XML metadata.

4

What can be done if patching is not immediately possible?

Avoid processing untrusted media files with the affected getID3 XML2array functionality on PHP versions before 8.0. Restricting attacker-controlled media ingestion reduces exposure to local-file disclosure, server-side request forgery, and entity-expansion denial of service.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203