Kapil Shewate created CASSANDRA-21690:
-----------------------------------------

             Summary: CVE-2026-56817.Netty is a network application framework 
for development of protocol servers and clients. In versions 4.2.0.Final 
through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can 
deliver bytes to a Netty channel pipeline
                 Key: CASSANDRA-21690
                 URL: https://issues.apache.org/jira/browse/CASSANDRA-21690
             Project: Apache Cassandra
          Issue Type: Bug
            Reporter: Kapil Shewate


CVE-2026-56817

Netty is a network application framework for development of protocol servers 
and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final 
through 4.1.135.Final, any caller that can deliver bytes to a Netty channel 
pipeline containing `XmlDecoder` can send XML with a `DOCTYPE` declaration to 
an `AsyncXMLInputFactory` instantiated with no security configuration, leaving 
DTD and entity handling active depending on Aalto XML async parser behavior and 
creating conditional XML external entity risk. This issue is fixed in versions 
4.1.136.Final and 4.2.16.Final.

 

Vulnerability reported by blackduck scan 

 
|apache-cassandra/lib/netty-all-4.1.130.Final.jar| | | |
|apache-cassandra/lib/netty-buffer-4.1.130.Final.jar| | | |
|apache-cassandra/lib/netty-codec-4.1.130.Final.jar| | | |
|apache-cassandra/lib/netty-common-4.1.130.Final.jar| | |
|apache-cassandra/lib/netty-handler-4.1.130.Final.jar| | | |
|apache-cassandra/lib/netty-handler-proxy-4.1.130.Final.jar| | |
|apache-cassandra/lib/netty-resolver-4.1.130.Final.jar| | | |
|apache-cassandra/lib/netty-transport-4.1.130.Final.jar| | |
|apache-cassandra/lib/netty-transport-native-epoll-4.1.130.Final-linux-aarch_64.jar|
|apache-cassandra/lib/netty-transport-native-epoll-4.1.130.Final-linux-x86_64.jar|
|apache-cassandra/lib/netty-transport-native-epoll-4.1.130.Final.jar| |



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to