An XML External Entity (XXE) vulnerability in the deserializeArgs() method of Java SDK for CloudEvents v4.0.1 allows attackers to access sensitive information via supplying a crafted XML-formatted event message.
https://github.com/aixiao0621/CVE/blob/main/CVE-2024-55156/README.md