CVE Explorer
CVE-2026-56817
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a `DOCTYPE` declaration to an `AsyncXMLInputFactory` instantiated with no security configuration, leaving DTD and entity handling active depending on Aalto XML async parser behavior and creating conditional XML external en
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"netty","vendor":"netty","versions":[{"status":"affected","version":">= 4.2.0.Final, < 4.2.16.Final"},{"status":"affected","version":">= 4.1.0.Final, < 4.1.136.Final"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d9779108925b5a2c77bc1615e1d0db21500c129556aae3e8ff8b6f4ad021c79d · sha256:30d9024e6006ea41… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":8.3,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d9779108925b5a2c77bc1615e1d0db21500c129556aae3e8ff8b6f4ad021c79d · sha256:30d9024e6006ea41… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-611","description":"CWE-611: Improper Restriction of XML External Entity Reference","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d9779108925b5a2c77bc1615e1d0db21500c129556aae3e8ff8b6f4ad021c79d · sha256:30d9024e6006ea41… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"name":"https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b","tags":["x_refsource_MISC"],"url":"https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d9779108925b5a2c77bc1615e1d0db21500c129556aae3e8ff8b6f4ad021c79d · sha256:30d9024e6006ea41… · /containers/cna/references/1
{"name":"https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6","tags":["x_refsource_MISC"],"url":"https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d9779108925b5a2c77bc1615e1d0db21500c129556aae3e8ff8b6f4ad021c79d · sha256:30d9024e6006ea41… · /containers/cna/references/2
{"name":"https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","tags":["x_refsource_MISC"],"url":"https://github.com/netty/netty/releases/tag/netty-4.1.136.Final"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d9779108925b5a2c77bc1615e1d0db21500c129556aae3e8ff8b6f4ad021c79d · sha256:30d9024e6006ea41… · /containers/cna/references/3
{"name":"https://github.com/netty/netty/releases/tag/netty-4.2.16.Final","tags":["x_refsource_MISC"],"url":"https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d9779108925b5a2c77bc1615e1d0db21500c129556aae3e8ff8b6f4ad021c79d · sha256:30d9024e6006ea41… · /containers/cna/references/4
{"name":"https://github.com/netty/netty/security/advisories/GHSA-4qhr-g3c6-fcfx","tags":["x_refsource_CONFIRM"],"url":"https://github.com/netty/netty/security/advisories/GHSA-4qhr-g3c6-fcfx"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d9779108925b5a2c77bc1615e1d0db21500c129556aae3e8ff8b6f4ad021c79d · sha256:30d9024e6006ea41… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.