CVE-2026-56817
Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enabled
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a `DOCTYPE` declaration to an `AsyncXMLInputFactory` instantiated with no security configuration, leaving DTD and entity handling active depending on Aalto XML async parser behavior and creating conditional XML external entity risk. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
| CWE | CWE-611 |
| Vendor | netty |
| Product | netty |
| Published | Jul 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for netty netty
Be the first to know when new unknown vulnerabilities affecting netty netty are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
netty / netty
>= 4.2.0.Final, < 4.2.16.Final >= 4.1.0.Final, < 4.1.136.Final
References
github.com: https://github.com/netty/netty/security/advisories/GHSA-4qhr-g3c6-fcfx github.com: https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b github.com: https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6 github.com: https://github.com/netty/netty/releases/tag/netty-4.1.136.Final github.com: https://github.com/netty/netty/releases/tag/netty-4.2.16.Final