Junglewise Threat Intelligence

CVE-2024-55875: http4k XXE and DoS in XML parsing

CVE-2024-55875 · Severity: critical · CVSS 9.8 · Published 2024-12-12

Vendors: Maven, Http4k.

Executive brief

A vulnerability exists in the http4k library, a toolkit used for building Kotlin HTTP applications. When processing XML data from users, the library does not properly restrict external entities or document type declarations. This could allow an attacker to read sensitive files from the server, perform unauthorized internal network requests, or cause a service outage through resource exhaustion.

Technical details

The http4k-format-xml module uses a DocumentBuilderFactory that, by default, does not disable external entity resolution or DTD processing. An unauthenticated remote attacker can send a crafted XML payload to an endpoint using Body.xml() or Document.asXmlDocument() to trigger XXE, leading to SSRF or local file disclosure. While initial fixes (v5.41.0.0) addressed external entities, a residual gap allowed for 'billion laughs' style internal entity expansion attacks. The final fix in v6.50.0.0 fully mitigates these by setting disallow-doctype-decl=true and FEATURE_SECURE_PROCESSING=true.

Affected products

  • http4k http4k-format-xml < 6.50.0.0

Timeline

  • 2024-12-12: advisory: Initial advisory published for XXE vulnerability
  • 2024-12-12: patched: Initial fix released in v5.41.0.0 / v4.50.0.0
  • 2026-05-31: patched: Follow-up patch v6.50.0.0 released to address residual DoS risks

References