Compliance Node Overview
MITRE CAPEC-228 (DTD Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker injects malicious content into an application's DTD in an attempt to produce a negative technical impact. DTDs are used to describe how XML documents are processed. Certain malformed DTDs (for example, those with excessive entity expansion as described in CAPEC 197) can cause the XML parsers that process the DTDs to consume excessive resources resulting in resource depletion. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-829.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/228.html
SHA-256 integrity: d35ba9b266b6741fcb42e4797e2ba44bee82f32d43e6dc52697cb289916931b3
Primary Citations — 7 traced to source
- MITRE CAPEC-228: DTD Injection (https://capec.mitre.org/data/definitions/228.html)
- CWE-829: underlying weakness (http://cwe.mitre.org/data/definitions/829.html)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.