{"id":"CVE-2013-4179","aliases":["GHSA-j6xh-q826-55jw","PYSEC-2026-875"],"url":"https://o3.security/vulnerability/CVE-2013-4179","summary":"OpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack","details":"The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.  NOTE: this issue is due to an incomplete fix for CVE-2013-1664.","published":"2013-09-16T19:14:38Z","modified":"2026-07-07T11:56:44.912257147Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"nova","fixedVersion":"2013.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2013-1199.html"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-2005-1"},{"type":"EVIDENCE","url":"https://bugs.launchpad.net/ossa/+bug/1190229"},{"type":"FIX","url":"http://rhn.redhat.com/errata/RHSA-2013-1199.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T11:56:44.912257147Z"}}