PT-2026-98218 · Unknown · Http4S-Scala-Xml

CVE-2026-61741

·

Published

2026-09-24

·

Updated

2026-09-29

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions http4s-scala-xml versions prior to 0.24.1 http4s-scala-xml versions prior to 1.0.0-M39
Description EntityDecoder[F, scala.xml.Elem] instances used to parse XML message bodies utilize a javax.xml.parsers.SAXParserFactory without security configuration. By default, the parser resolves DOCTYPE declarations, external general and parameter entities, and external DTDs. This allows an attacker to perform XML External Entity (XXE) attacks, which can lead to the disclosure of local files, server-side request forgery (SSRF) against internal network resources, or denial of service through entity expansion.
Recommendations Update to version 0.24.1 or later. Update to version 1.0.0-M39 or later. As a temporary workaround, override ElemInstances#saxFactory with a hardened factory that disables DOCTYPE declarations and external entities.

Exploit

Fix

DoS

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61741
GHSA-CJX3-73HR-RPW7

Affected Products

Http4S-Scala-Xml