{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/netty-codec-xml-4.2.0.final---4.2.15.final/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-56817"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["netty-codec-xml (4.1.0.Final - 4.1.135.Final)","netty-codec-xml (4.2.0.Final - 4.2.15.Final)"],"_cs_severities":["high"],"_cs_tags":["netty","xml","xxe","vulnerability","java","server-side","web-application"],"_cs_type":"advisory","_cs_vendors":["Netty"],"content_html":"\u003cp\u003eA high-severity misconfiguration vulnerability, tracked as CVE-2026-56817, exists within the \u003ccode\u003eXmlDecoder\u003c/code\u003e component of the Netty framework's \u003ccode\u003enetty-codec-xml\u003c/code\u003e library. This flaw allows any attacker capable of delivering bytes to a Netty channel pipeline containing \u003ccode\u003eXmlDecoder\u003c/code\u003e to send specially crafted XML. The vulnerability arises because the XML factory used by \u003ccode\u003eXmlDecoder\u003c/code\u003e can be instantiated without proper security configuration, enabling active Document Type Definition (DTD) and external entity handling. This permits the submission of XML payloads containing \u003ccode\u003eDOCTYPE\u003c/code\u003e declarations that refer to external entities, a common vector for XML External Entity (XXE) injection attacks. The exploitability is conditional, depending on whether the underlying Aalto XML parser resolves these external entities. Affected versions include \u003ccode\u003enetty-codec-xml\u003c/code\u003e from 4.1.0.Final up to and including 4.1.135.Final, and from 4.2.0.Final up to and including 4.2.15.Final. This vulnerability could lead to information disclosure, server-side request forgery (SSRF), or other impacts.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies a Netty-based application that accepts XML input and uses a vulnerable version of the \u003ccode\u003enetty-codec-xml\u003c/code\u003e library.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious XML payload containing a \u003ccode\u003e\u0026lt;!DOCTYPE\u003c/code\u003e declaration with an external entity reference (e.g., \u003ccode\u003e\u0026lt;!ENTITY xxe SYSTEM \u0026quot;file:///path/to/sensitive/file\u0026quot;\u0026gt;\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe attacker sends this crafted XML payload, typically via an HTTP POST request, to the vulnerable Netty application's endpoint.\u003c/li\u003e\n\u003cli\u003eThe Netty application's channel pipeline receives the input bytes and routes them to the \u003ccode\u003eXmlDecoder\u003c/code\u003e component for processing.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eXmlDecoder\u003c/code\u003e processes the XML using an underlying parser (such as Aalto XML) that has been instantiated with no security configuration, allowing it to handle DTDs and resolve external entities.\u003c/li\u003e\n\u003cli\u003eIf the specific configuration and runtime behavior of the Aalto XML parser resolve external entities, the attacker-controlled external entity reference is processed.\u003c/li\u003e\n\u003cli\u003eThis processing can lead to information disclosure (e.g., reading local files or internal network resources) or Server-Side Request Forgery (SSRF) if the entity points to remote URLs, impacting the confidentiality and integrity of the application.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-56817 can lead to XML External Entity (XXE) injection, which primarily results in information disclosure. Attackers may be able to read arbitrary files on the vulnerable server, potentially exposing sensitive data, configuration files, or credentials. Depending on the server's network configuration and the capabilities of the XML parser, attackers might also be able to perform Server-Side Request Forgery (SSRF) to access internal network resources or external services, or initiate port scans. While the exploitability is conditional, affected organizations face a significant risk of data exfiltration and unauthorized access to internal systems if the vulnerable Netty applications are internet-facing or process untrusted XML input.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-56817 by updating \u003ccode\u003enetty-codec-xml\u003c/code\u003e to a non-vulnerable version (e.g., 4.1.136.Final or 4.2.16.Final) immediately.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detects CVE-2026-56817 Exploitation - HTTP POST with DOCTYPE Declaration\u0026quot; to your SIEM to identify attempts at XXE injection.\u003c/li\u003e\n\u003cli\u003eEnable comprehensive webserver logging to capture HTTP request bodies for analysis of XML payloads.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T21:47:02Z","date_published":"2026-07-22T21:47:02Z","id":"https://feed.craftedsignal.io/briefs/2026-07-netty-xml-injection/","summary":"A misconfiguration vulnerability (CVE-2026-56817) in Netty's XmlDecoder component allows attackers to send XML with DOCTYPE declarations to an unconfigured XML factory, potentially leading to XML External Entity (XXE) injection if the underlying Aalto XML parser resolves external entities, impacting Netty applications using `netty-codec-xml` versions 4.1.0.Final through 4.1.135.Final and 4.2.0.Final through 4.2.15.Final.","title":"Netty XML Injection Vulnerability (CVE-2026-56817)","url":"https://feed.craftedsignal.io/briefs/2026-07-netty-xml-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Netty-Codec-Xml (4.2.0.Final - 4.2.15.Final)","version":"https://jsonfeed.org/version/1.1"}