CVE-2026-61741
Last modified
CVE-2026-61741 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInstance` without any security configuration.
Description
http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInstance` without any security configuration. With the JDK's default settings, the parser resolves DOCTYPE declarations, external general and parameter entities, and external DTDs.An application that uses these decoders to parse untrusted XML is vulnerable to XML External Entity (XXE) attacks. An attacker can craft a request that discloses local files readable by the service process, performs server-side request forgery (SSRF) against internal network resources, and/or causes denial of service through entity expansion. Versions 0.24.1 and 1.0.0-M39 fix the issue.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| http4s | http4s-scala-xml | < 0.24.1; >= 1.0.0-M1, < 1.0.0-M39 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-61741?
How severe is CVE-2026-61741?
How do I fix CVE-2026-61741?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-61722FluidSynth is a software synthesizer based on the SoundFont …6.8
- CVE-2026-61723FluidSynth is a software synthesizer based on the SoundFont …6.8
- CVE-2026-61732Decepticon is an autonomous hacking agent for red teams. Ver…10
- CVE-2026-61736LightRAG provides simple and fast retrieval-augmented genera…9.3
- CVE-2026-6174The CC Child Pages plugin for WordPress is vulnerable to Sto…6.4
- CVE-2026-61740LightRAG provides simple and fast retrieval-augmented genera…9.3
- CVE-2026-61742DBHub is a database MCP server for Postgres, MySQL, SQL Serv…9.3
- CVE-2026-61743Chartbrew is an open-source web application that can connect…6.3
- CVE-2026-61744InvenTree is an Open Source Inventory Management System. Pri…6.5
- CVE-2026-61745InvenTree is an Open Source Inventory Management System. Pri…4.3
- CVE-2026-61746InvenTree is an Open Source Inventory Management System. Pri…5.3
- CVE-2026-61747InvenTree is an Open Source Inventory Management System. Pri…4.3
Are you affected by CVE-2026-61741?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
