PT-2026-98218 · Unknown · Http4S-Scala-Xml
CVE-2026-61741
·
Published
2026-09-24
·
Updated
2026-09-29
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
http4s-scala-xml versions prior to 0.24.1
http4s-scala-xml versions prior to 1.0.0-M39
Description
EntityDecoder[F, scala.xml.Elem] instances used to parse XML message bodies utilize a javax.xml.parsers.SAXParserFactory without security configuration. By default, the parser resolves DOCTYPE declarations, external general and parameter entities, and external DTDs. This allows an attacker to perform XML External Entity (XXE) attacks, which can lead to the disclosure of local files, server-side request forgery (SSRF) against internal network resources, or denial of service through entity expansion.Recommendations
Update to version 0.24.1 or later.
Update to version 1.0.0-M39 or later.
As a temporary workaround, override
ElemInstances#saxFactory with a hardened factory that disables DOCTYPE declarations and external entities.Exploit
Fix
DoS
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Http4S-Scala-Xml