CVE-2026-61741 | http4s http4s-scala-xml up to 0.24.0/1.0.0-M38 EntityDecoder xml external entity reference

SecurityVulns

A vulnerability was found in http4s http4s-scala-xml up to 0.24.0/1.0.0-M38. It has been rated as critical. This affects an unknown function of the component EntityDecoder. The manipulation leads to xml external entity reference.

This vulnerability is listed as CVE-2026-61741. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is advised.VulDB Recent EntriesRead More