Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a `DOCTYPE` declaration to an `AsyncXMLInputFactory` instantiated with no security configuration, leaving DTD and entity handling active depending on Aalto XML async parser behavior and creating conditional XML external entity risk. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
References
Configurations
Configuration 1 (hide)
|
History
30 Jul 2026, 14:48
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b - Patch | |
| References | () https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6 - Patch | |
| References | () https://github.com/netty/netty/releases/tag/netty-4.1.136.Final - Release Notes | |
| References | () https://github.com/netty/netty/releases/tag/netty-4.2.16.Final - Release Notes | |
| References | () https://github.com/netty/netty/security/advisories/GHSA-4qhr-g3c6-fcfx - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| CPE | cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* | |
| First Time |
Netty netty
Netty |
21 Jul 2026, 23:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-21 23:17
Updated : 2026-07-30 14:48
NVD link : CVE-2026-56817
Mitre link : CVE-2026-56817
CVE.ORG link : CVE-2026-56817
JSON object : View
Products Affected
netty
- netty
CWE
CWE-611
Improper Restriction of XML External Entity Reference
