CVE-2026-56817
ADVISORY - githubSummary
Any caller that can deliver bytes to a Netty channel pipeline containing XmlDecoder can send XML with a DOCTYPE declaration to a parser instantiated with no security configuration — but whether external entities are actually resolved depends on Aalto XML's async parser behavior, making this a confirmed misconfiguration with conditional exploitability.
Common Weakness Enumeration (CWE)
ADVISORY - github
Improper Restriction of XML External Entity Reference
GitHub
CREATED
UPDATED
ADVISORY IDGHSA-4qhr-g3c6-fcfx
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)