GHSA-cjx3-73hr-rpw7: http4s-scala-xml has an XML External Entity (XXE) processing issue
HIGHCritical vulnerability — CVSS 9.3
What to do
- Critical severity — schedule an urgent patch.
http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. These decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInstance` without any security configuration. With the JDK's default settings, the parser resolves DOCTYPE declarations, external general and parameter entities, and external DTDs. An application that uses these decoders to parse untrusted XML is vulnerable to XML External Entity (XXE) attacks. …
CVE · detail
Early access
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.
bot-protected