parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities. https://nvd.nist.gov/vuln/detail/CVE-2017-16932