CVE-2024-55156
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
An XML External Entity (XXE) vulnerability in the deserializeArgs() method of Java SDK for CloudEvents v4.0.1 allows attackers to access sensitive information via supplying a crafted XML-formatted event message.
Published 2025-02-21. Last modified 2026-06-17.