PT-2026-63257 · Netty · Netty

CVE-2026-56817

·

Published

2026-07-21

·

Updated

2026-07-21

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Netty versions 4.1.0.Final through 4.1.135.Final Netty versions 4.2.0.Final through 4.2.15.Final
Description An issue exists where a caller delivering bytes to a channel pipeline containing XmlDecoder can send XML with a DOCTYPE declaration to an AsyncXMLInputFactory that lacks security configuration. This leaves Document Type Definition (DTD) and entity handling active, depending on the Aalto XML async parser behavior, which creates a conditional XML external entity (XXE) risk. XXE is a type of attack that allows an attacker to interfere with an application's processing of XML data.
Recommendations Update Netty versions 4.1.0.Final through 4.1.135.Final to version 4.1.136.Final. Update Netty versions 4.2.0.Final through 4.2.15.Final to version 4.2.16.Final.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56817
GHSA-4QHR-G3C6-FCFX

Affected Products

Netty