A critical vulnerability affecting http4s-scala-xml_2.12 versions <= 0.24.0 affecting http4s-scala-xml_2.13 versions <= 0.24.0, CVE-2026-61741 with a CVSS score of 9.3, has been identified in http4s-scala-xml due to an XML External Entity (XXE) processing issue caused by the use of a javax.xml.parsers.SAXParserFactory obtained from SAXParserFactory.newInstance without any security configuration. This allows an attacker to craft a request that discloses local files readable by the service process, performs server-side request forgery (SSRF) against internal network resources, and/or causes denial of service through entity expansion. Any service that derives an XML EntityDecoder from this library and parses attacker-controlled input is affected, resulting in significant business impact due to potential data breaches and system compromise.
We recommend you to refer this link: https://github.com/http4s/http4s-scala-xml/releases/tag/v0.24.1[/subscribe_to_unlock_form]
A critical vulnerability affecting http4s-scala-xml_2.12 versions <= 0.24.0 affecting http4s-scala-xml_2.13 versions <= 0.24.0, CVE-2026-61741 with a CVSS score of 9.3, has been identified in http4s-scala-xml due to an XML External Entity (XXE) processing issue caused by the use of a javax.xml.parsers.SAXParserFactory obtained from SAXParserFactory.newInstance without any security configuration. This allows an attacker to craft a request that discloses local files readable by the service process, performs server-side request forgery (SSRF) against internal network resources, and/or causes denial of service through entity expansion. Any service that derives an XML EntityDecoder from this library and parses attacker-controlled input is affected, resulting in significant business impact due to potential data breaches and system compromise.
We recommend you to refer this link: https://github.com/http4s/http4s-scala-xml/releases/tag/v0.24.1[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]