CVE-2024-55875
http4k XXE Vulnerability Allows Sensitive Data Disclosure and Server-Side Request Forgery
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A vulnerability in the http4k toolkit for Kotlin HTTP applications allows for denial-of-service attacks when processing untrusted XML. Attackers can exploit this by sending specially crafted XML with doctype declarations, potentially exhausting server resources. Readers should verify if their Kotlin HTTP applications u