UNKNOWN Maven

Netty XML: Injection / Risky Sink — unconfigured XML factory with active DTD and entity handling

GHSA-4qhr-g3c6-fcfx · CVE-2026-56817

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Any caller that can deliver bytes to a Netty channel pipeline containing XmlDecoder can send XML with a DOCTYPE declaration to a parser instantiated with no security configuration — but whether external entities are actually resolved depends on Aalto XML's async parser behavior, making this a confirmed misconfiguration with conditional exploitability.

Ready to move

Start Securing

Free, no credit card | First findings in minutes