XML External Entity Vulnerability in http4s-scala-xml by Http4s
CVE-2026-61741

9.3CRITICAL

Key Information:

Vendor

Http4s

Vendor
CVE Published:
24 September 2026

What is CVE-2026-61741?

The http4s-scala-xml library's XML parsing capabilities are compromised due to the usage of a javax.xml.parsers.SAXParserFactory without adequate security configurations. Earlier versions allow for the resolution of DOCTYPE declarations and external entities, making applications that rely on these decoders for parsing untrusted XML messages susceptible to malicious attacks. Threats include unauthorized access to local files, server-side request forgery (SSRF) potential, and denial of service via entity expansion techniques. Users are advised to upgrade to versions 0.24.1 or 1.0.0-M39, which have addressed these security concerns.

Affected Version(s)

http4s-scala-xml < 0.24.1 < 0.24.1

http4s-scala-xml >= 1.0.0-M1, < 1.0.0-M39 < 1.0.0-M1, 1.0.0-M39

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.