Threat Advisory

http4s Scala XML Flaw Lets Attackers Read Local Files

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical vulnerability affecting http4s-scala-xml_2.12 versions <= 0.24.0 affecting http4s-scala-xml_2.13 versions <= 0.24.0, CVE-2026-61741 with a CVSS score of 9.3, has been identified in http4s-scala-xml due to an XML External Entity (XXE) processing issue caused by the use of a javax.xml.parsers.SAXParserFactory obtained from SAXParserFactory.newInstance without any security configuration. This allows an attacker to craft a request that discloses local files readable by the service process, performs server-side request forgery (SSRF) against internal network resources, and/or causes denial of service through entity expansion. Any service that derives an XML EntityDecoder from this library and parses attacker-controlled input is affected, resulting in significant business impact due to potential data breaches and system compromise.

RECOMMENDATION:

We recommend you to refer this link: https://github.com/http4s/http4s-scala-xml/releases/tag/v0.24.1[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical vulnerability affecting http4s-scala-xml_2.12 versions <= 0.24.0 affecting http4s-scala-xml_2.13 versions <= 0.24.0, CVE-2026-61741 with a CVSS score of 9.3, has been identified in http4s-scala-xml due to an XML External Entity (XXE) processing issue caused by the use of a javax.xml.parsers.SAXParserFactory obtained from SAXParserFactory.newInstance without any security configuration. This allows an attacker to craft a request that discloses local files readable by the service process, performs server-side request forgery (SSRF) against internal network resources, and/or causes denial of service through entity expansion. Any service that derives an XML EntityDecoder from this library and parses attacker-controlled input is affected, resulting in significant business impact due to potential data breaches and system compromise.

RECOMMENDATION:

We recommend you to refer this link: https://github.com/http4s/http4s-scala-xml/releases/tag/v0.24.1[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu