CVE-2026-61741 | http4s http4s-scala-xml up to 0.24.0/1.0.0-M38 EntityDecoder xml external entity reference
A vulnerability was found in http4s http4s-scala-xml up to 0.24.0/1.0.0-M38. It has been rated as critical. This affects an unknown function of the component EntityDecoder. The manipulation leads to xml external entity reference.
This vulnerability is listed as CVE-2026-61741. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.VulDB Recent EntriesRead More