External risk intelligence

http4s-scala-xml XXE Vulnerability Allows File Disclosure and SSRF.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-61741

The vulnerability exists in a library used to parse XML message bodies in web applications. Because http4s is a common framework for building internet-facing web services and APIs, applications utilizing these decoders to process untrusted XML input are often reachable from the public internet.

XML External Entity Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in widely used XML parsing libraries within http4s-scala-xml, potentially exposing applications to significant risks. When processing untrusted XML data, affected systems may be vulnerable to attacks that could lead to the disclosure of sensitive local files, unauthorized access to internal network resources, or denial of service. The primary concern is to confirm if our systems utilize these specific vulnerable components for handling external XML inputs, as the library is commonly used for internet-facing web services and APIs.

  • XML parsing flaw allows data theft or system disruption.
  • Affects common web services processing external XML.
  • Confirm relevance and exposure for affected systems.

Attack Path

How an attacker could exploit the issue

An attacker can target web applications that use http4s-scala-xml to process XML data. By sending a specially crafted XML request, an attacker can exploit the XML parser's default behavior, which resolves external entities. This can lead to the disclosure of sensitive files, unauthorized access to internal resources, or disruption of the service.

  • Requires network access to the application.
  • Triggered by sending a malicious XML payload.
  • Risk of data exposure and service disruption.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to gain access to sensitive information, disrupt services, or target internal network resources by exploiting how XML data is processed. This occurs when an application uses affected http4s-scala-xml decoders to parse untrusted XML, enabling the attacker to inject malicious entities.

  • Local files readable by the service process.
  • Untrusted XML input is parsed.
  • Disclosure of files, SSRF, or DoS.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in `http4s-scala-xml` affects applications that parse untrusted XML, potentially leading to data disclosure, SSRF, or denial of service. Ownership of this issue likely falls to the application or service owner responsible for the code using the affected library, in coordination with the platform or infrastructure team managing the underlying services. The first practical step is to identify all services utilizing the library, assess their exposure and criticality, and then plan remediation within a maintenance window, involving vendor coordination if necessary.

  • Application owners should own the remediation effort.
  • Verify vulnerable library usage and network exposure.
  • Plan for remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is http4s-scala-xml?

It is a library used in Scala applications to handle XML data. Developers use it to convert XML message bodies into usable code objects. It is frequently employed within web services and APIs to interpret incoming data, making it a common component for applications that need to communicate using XML formats.

How does CVE-2026-61741 work?

This vulnerability involves Improper Restriction of XML External Entity References, or CWE-611. Because the library's XML parser defaults to insecure settings, it follows instructions hidden inside XML data that point to external files or network addresses. This allows an attacker to trick the server into reading local files or accessing internal network resources it was never meant to reach.

What triggers this XML vulnerability?

An attacker triggers this by sending a specially crafted XML request to an endpoint that uses the affected decoder. Simply having the library installed is not enough; the bug only activates when the application actually processes untrusted XML input from a user or external source. If your service does not parse incoming XML, it is not susceptible to this trigger.

Is my application at risk for CVE-2026-61741?

Halo Surface Signal indicates that because http4s is often used for building internet-facing services, applications using these decoders for untrusted input are likely reachable from the public internet. If your service exposes an interface that accepts XML from the web, you should assume a higher risk level compared to internal-only systems that do not interact with public traffic.

How do I address this CVE-2026-61741 risk?

Your first step is to perform a dependency audit to identify if your services rely on vulnerable versions of the library. Once identified, you should update to version 0.24.1 or 1.0.0-M39, which contain the necessary security configurations to disable dangerous XML parsing behaviors. Coordinate this update within your standard maintenance window to ensure stability.

References