{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/http4s-scala-xml--0.24.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:http4s:http4s_scala_xml:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.3,"id":"CVE-2026-61741"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["http4s-scala-xml (\u003c= 0.24.0)","http4s-scala-xml (\u003e= 1.0.0-M1, \u003c= 1.0.0-M38.1)"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","web-application","xxe","cve-2026-61741"],"_cs_type":"advisory","_cs_vendors":["http4s"],"content_html":"\u003cp\u003eThe http4s-scala-xml library (versions \u0026lt;= 0.24.0 and 1.0.0-M1 through 1.0.0-M38.1) contains a critical XML External Entity (XXE) vulnerability identified as CVE-2026-61741. The issue stems from the use of an unhardened \u003ccode\u003ejavax.xml.parsers.SAXParserFactory\u003c/code\u003e within the library's \u003ccode\u003eEntityDecoder\u003c/code\u003e. Because the parser is initialized without explicit security constraints, it defaults to processing DOCTYPE declarations, external general/parameter entities, and DTDs.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated remote attacker can exploit this by submitting malformed XML payloads to an application leveraging these decoders. If successfully exploited, this allows the attacker to read arbitrary local files accessible to the service, conduct server-side request forgery (SSRF) against internal services, or trigger a denial-of-service condition via excessive entity expansion. This vulnerability affects any Scala application utilizing the library for processing untrusted XML inputs.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the exfiltration of sensitive local files from the application server, unauthorized interaction with internal network resources (SSRF), and system instability through resource exhaustion. This impacts any environment using http4s-scala-xml to process user-supplied XML data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to a non-vulnerable version of http4s-scala-xml immediately.\u003c/li\u003e\n\u003cli\u003eIf an upgrade is not immediately feasible, override the \u003ccode\u003eElemInstances#saxFactory\u003c/code\u003e with a hardened configuration that explicitly disables DTD loading and external entity processing using the \u003ccode\u003ejavax.xml.parsers.SAXParserFactory\u003c/code\u003e feature flags (e.g., \u003ccode\u003ehttp://apache.org/xml/features/disallow-doctype-decl\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eImplement input validation for any XML endpoints to detect and reject payloads containing \u003ccode\u003eDOCTYPE\u003c/code\u003e declarations.\u003c/li\u003e\n\u003cli\u003eAudit application logs for abnormal outgoing network traffic from the web service process, which may indicate attempted SSRF exploitation via CVE-2026-61741.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T20:04:02Z","date_published":"2026-09-24T20:04:02Z","id":"https://feed.craftedsignal.io/briefs/2026-09-http4s-xxe/","summary":"The http4s-scala-xml library is vulnerable to XML External Entity (XXE) attacks due to improper configuration of the SAXParserFactory, allowing unauthenticated attackers to perform SSRF or local file disclosure.","title":"XXE Vulnerability in http4s-scala-xml","url":"https://feed.craftedsignal.io/briefs/2026-09-http4s-xxe/"}],"language":"en","title":"CraftedSignal Threat Feed - Http4s-Scala-Xml (\u003c= 0.24.0)","version":"https://jsonfeed.org/version/1.1"}