CVE-2026-61741
Published:September 24, 2026
Updated:October 09, 2026
http4s-scala-xml provides "EntityDecoder[F, scala.xml.Elem]" instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a "javax.xml.parsers.SAXParserFactory" obtained from "SAXParserFactory.newInstance" without any security configuration. With the JDK's default settings, the parser resolves DOCTYPE declarations, external general and parameter entities, and external DTDs.An application that uses these decoders to parse untrusted XML is vulnerable to XML External Entity (XXE) attacks. An attacker can craft a request that discloses local files readable by the service process, performs server-side request forgery (SSRF) against internal network resources, and/or causes denial of service through entity expansion. Versions 0.24.1 and 1.0.0-M39 fix the issue.
Affected Packages
org.http4s:http4s-scala-xml_3 (JAVA):
Affected version(s) >=1.0.0-M22 <1.0.0-M39Fix Suggestion:
Update to version 1.0.0-M39org.http4s:http4s-scala-xml_2.13 (JAVA):
Affected version(s) >=1.0.0-M2 <1.0.0-M39Fix Suggestion:
Update to version 1.0.0-M39org.http4s:http4s-scala-xml_3 (JAVA):
Affected version(s) >=0.22.0-M8 <0.24.1Fix Suggestion:
Update to version 0.24.1org.http4s:http4s-scala-xml_2.13 (JAVA):
Affected version(s) >=0.10.0-M10 <0.24.1Fix Suggestion:
Update to version 0.24.1org.http4s:http4s-scala-xml_2.12 (JAVA):
Affected version(s) >=0.10.0-M10 <0.24.1Fix Suggestion:
Update to version 0.24.1Related Resources (7)
Do you need more information?
Contact UsCVSS v4
Base Score:
9.2
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
HIGH
Vulnerable System Integrity
NONE
Vulnerable System Availability
LOW
Subsequent System Confidentiality
HIGH
Subsequent System Integrity
NONE
Subsequent System Availability
LOW
CVSS v3
Base Score:
9.3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
LOW
Weakness Type (CWE)
Improper Restriction of XML External Entity Reference
EPSS
Base Score:
0.29