๐Ÿ” CVE Alert

CVE-2026-61741

CRITICAL 9.3

http4s-scala-xml has an XML External Entity (XXE) processing issue

CVSS Score
9.3
EPSS Score
0.0%
EPSS Percentile
0th

http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInstance` without any security configuration. With the JDK's default settings, the parser resolves DOCTYPE declarations, external general and parameter entities, and external DTDs.An application that uses these decoders to parse untrusted XML is vulnerable to XML External Entity (XXE) attacks. An attacker can craft a request that discloses local files readable by the service process, performs server-side request forgery (SSRF) against internal network resources, and/or causes denial of service through entity expansion. Versions 0.24.1 and 1.0.0-M39 fix the issue.

CWE CWE-611
Vendor http4s
Product http4s-scala-xml
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for http4s http4s-scala-xml

Be the first to know when new critical vulnerabilities affecting http4s http4s-scala-xml are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
Low

Affected Versions

http4s / http4s-scala-xml
< 0.24.1 >= 1.0.0-M1, < 1.0.0-M39

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/http4s/http4s-scala-xml/security/advisories/GHSA-cjx3-73hr-rpw7