XML External Entity Vulnerability in http4s-scala-xml by Http4s
CVE-2026-61741
9.3CRITICAL
What is CVE-2026-61741?
The http4s-scala-xml library's XML parsing capabilities are compromised due to the usage of a javax.xml.parsers.SAXParserFactory without adequate security configurations. Earlier versions allow for the resolution of DOCTYPE declarations and external entities, making applications that rely on these decoders for parsing untrusted XML messages susceptible to malicious attacks. Threats include unauthorized access to local files, server-side request forgery (SSRF) potential, and denial of service via entity expansion techniques. Users are advised to upgrade to versions 0.24.1 or 1.0.0-M39, which have addressed these security concerns.
Affected Version(s)
http4s-scala-xml < 0.24.1 < 0.24.1
http4s-scala-xml >= 1.0.0-M1, < 1.0.0-M39 < 1.0.0-M1, 1.0.0-M39
