PT-2026-63257 · Netty · Netty
CVE-2026-56817
·
Published
2026-07-21
·
Updated
2026-07-21
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Netty versions 4.1.0.Final through 4.1.135.Final
Netty versions 4.2.0.Final through 4.2.15.Final
Description
An issue exists where a caller delivering bytes to a channel pipeline containing
XmlDecoder can send XML with a DOCTYPE declaration to an AsyncXMLInputFactory that lacks security configuration. This leaves Document Type Definition (DTD) and entity handling active, depending on the Aalto XML async parser behavior, which creates a conditional XML external entity (XXE) risk. XXE is a type of attack that allows an attacker to interfere with an application's processing of XML data.Recommendations
Update Netty versions 4.1.0.Final through 4.1.135.Final to version 4.1.136.Final.
Update Netty versions 4.2.0.Final through 4.2.15.Final to version 4.2.16.Final.
Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netty