CVE-2024-55875 is an XML External Entity (XXE) vulnerability in http4k, specifically affecting XML parsing in the http4k-format-xml component prior to version 5.41.0.0. When an application using the vulnerable library parses attacker-controlled XML content in requests, unsafe XML parser behavior may allow external entity resolution. This can permit malicious XML payloads to cause the server to access local files or external resources. The issue affects servers that handle untrusted XML input through http4k’s XML parsing functionality.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (POC) for CVE-2024-55875, targeting the http4k framework for the JVM. The main file, Main.kt, implements a simple HTTP server on port 9000 that accepts XML payloads via POST requests. The server parses incoming XML without apparent protection against XML External Entity (XXE) attacks. The provided 'poc' file demonstrates exploitation by sending a crafted XML payload containing an external entity referencing a remote URL, which could be used to exfiltrate data or trigger remote resource access. The repository structure is minimal, consisting of the Kotlin server code, a README referencing the CVE, and a shell script with a curl command to trigger the vulnerability. The exploit is a POC and does not include weaponized or automated exploitation features.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.