Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4qhr-g3c6-fcfx

Опубликовано: 22 июл. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.3

Описание

Netty XML: Injection / Risky Sink — unconfigured XML factory with active DTD and entity handling

Any caller that can deliver bytes to a Netty channel pipeline containing XmlDecoder can send XML with a DOCTYPE declaration to a parser instantiated with no security configuration — but whether external entities are actually resolved depends on Aalto XML's async parser behavior, making this a confirmed misconfiguration with conditional exploitability.

Пакеты

Наименование

io.netty:netty-codec-xml

maven
Затронутые версииВерсия исправления

>= 4.2.0.Final, <= 4.2.15.Final

4.2.16.Final

Наименование

io.netty:netty-codec-xml

maven
Затронутые версииВерсия исправления

>= 4.1.0.Final, <= 4.1.135.Final

4.1.136.Final

EPSS

Процентиль: 30%
0.00371
Низкий

8.3 High

CVSS4

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 9.8
ubuntu
13 дней назад

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a `DOCTYPE` declaration to an `AsyncXMLInputFactory` instantiated with no security configuration, leaving DTD and entity handling active depending on Aalto XML async parser behavior and creating conditional XML external entity risk. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.

CVSS3: 7.5
redhat
13 дней назад

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a `DOCTYPE` declaration to an `AsyncXMLInputFactory` instantiated with no security configuration, leaving DTD and entity handling active depending on Aalto XML async parser behavior and creating conditional XML external entity risk. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.

CVSS3: 9.8
nvd
13 дней назад

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a `DOCTYPE` declaration to an `AsyncXMLInputFactory` instantiated with no security configuration, leaving DTD and entity handling active depending on Aalto XML async parser behavior and creating conditional XML external entity risk. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.

CVSS3: 9.8
debian
13 дней назад

Netty is a network application framework for development of protocol s ...

EPSS

Процентиль: 30%
0.00371
Низкий

8.3 High

CVSS4

Дефекты

CWE-611