Typelevel
Typelevel Http4s: vulnerabilities and CVEs
Typelevel Http4s has 27 published vulnerabilities, 20 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs27
Last 12 months20
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-88975 | High (7.5) | 0.63% | — | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’s 24-bit declared length but waits to buffer the entire payload before comparing it with… |
| CVE-2026-69218 | High (7.5) | 0.63% | — | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, When Ember receives an HTTP/2 HEADERS or PUSH_PROMISE frame without END_HEADERS, H2Connection buffers the header block and subsequent… |
| CVE-2026-69217 | High (8.7) | 0.50% | — | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/1.1 parser accepts differing duplicate Content-Length headers and uses the last value instead of rejecting the message. When an… |
| CVE-2026-69215 | Medium (6.8) | 0.51% | — | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware uses unanchored substring checks instead of RFC 6265 domain and path matching when deciding whether to… |
| CVE-2026-69210 | High (7.5) | 0.63% | — | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, WebSocket FrameTranscoder.bodyLength rejects extended payload lengths above Integer.MAX_VALUE but permits negative 64-bit lengths. A remote… |
| CVE-2026-69206 | Medium (5.9) | 0.40% | — | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, DigestAuth replay protection records lastNc plus one instead of the highest nonce-count value it has accepted. When a legitimate client… |
| CVE-2026-69205 | High (8.7) | 0.48% | — | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HeaderP.parse uses a case-sensitive substring test for the Transfer-Encoding value and decodes header bytes with the platform… |
| CVE-2026-69203 | High (7.5) | 0.63% | — | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, An Ember server with HTTP/2 enabled through withHttp2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS for peer-created streams. One… |
| CVE-2026-69202 | High (7.5) | 0.63% | — | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/2 flow-control window is replenished according to bytes received from the network rather than bytes consumed by the… |
| CVE-2026-69216 | Medium (5.4) | 0.37% | — | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s chunk decoder trims the chunk-size token and accepts leading plus or minus signs instead of requiring one or more hexadecimal digits… |
| CVE-2026-69214 | Medium (6.8) | 0.40% | — | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware stores a response cookie’s Domain attribute without checking that it domain-matches the host that supplied… |
| CVE-2026-69213 | High (7.5) | 0.63% | — | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames through one unbounded queue consumed by writeLoop. When the peer stops reading, an unauthenticated… |
| CVE-2026-69212 | Medium (5.9) | 0.28% | — | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The FollowRedirect client middleware strips Authorization and Cookie headers only when a redirect changes authority, but authority… |
| CVE-2026-69211 | Medium (4.8) | 0.33% | — | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResponseCookie.render writes attacker-influenced name, content, domain, path, and extension values without neutralizing semicolons or… |
| CVE-2026-69209 | High (7.5) | 0.63% | — | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The shared WebSocket decoder permits unbounded message buffering because defragmentation accumulates fragments without a limit and… |
| CVE-2026-69208 | High (7.5) | 0.77% | — | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, the DigestAuth server middleware removes fresh nonces and stops eviction at the first stale nonce because its stale-nonce comparison is… |
| CVE-2026-69204 | Critical (9.2) | 0.57% | — | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/1.1 does not reject messages containing both Transfer-Encoding and Content-Length, so an intermediary and Ember can select… |
| CVE-2026-69201 | Medium (5.9) | 0.76% | — | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResourceService and WebjarService decode each URL path segment but reject only segments exactly equal to an empty string, a dot, or two… |
| CVE-2026-54556 | High (8.2) | 0.52% | — | Aug 26, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, an unauthenticated HTTP/2 peer can cause an out-of-memory denial of service in the Ember backend with HTTP/2 enabled. The Hpack wrapper in… |
| CVE-2026-73495 | High (7.4) | 0.48% | — | Aug 12, 2026 | blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42, blaze-server can merge HTTP/1.1 chunked-body trailer fields into Request.headers. Because trailer… |
| CVE-2025-59822 | Medium (6.3) | 0.37% | — | Sep 23, 2025 | Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section. This… |
| CVE-2023-22465 | Medium (5.3) | 0.84% | — | Jan 4, 2023 | Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the `User-Agent` and `Server` header parsers are susceptible to a fatal error on… |
| CVE-2021-41084 | Medium (4.7) | 1.2% | — | Sep 21, 2021 | http4s is an open source scala interface for HTTP. In affected versions http4s is vulnerable to response-splitting or request-splitting attacks when untrusted user input is used to create any of the following fields:… |
| CVE-2021-39185 | Critical (9.1) | 0.59% | — | Sep 1, 2021 | Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0.22.2, 0.23.0, 0.23.1, and 1.0.0-M1 through 1.0.0-M24, the default CORS configuration is vulnerable… |
| CVE-2021-32643 | Medium (5.8) | 1.4% | — | May 27, 2021 | Http4s is a Scala interface for HTTP services. `StaticFile.fromUrl` can leak the presence of a directory on a server when the `URL` scheme is not `file://`, and the URL points to a fetchable resource under its scheme… |
| CVE-2021-21294 | High (7.5) | 2.1% | — | Feb 2, 2021 | Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Http4s before versions 0.21.17, 0.22.0-M2, and 1.0.0-M14 have a vulnerability which can lead to a denial-of-service. Blaze-core, a… |
| CVE-2020-5280 | High (7.5) | 7.0% | — | Mar 25, 2020 | http4s before versions 0.18.26, 0.20.20, and 0.21.2 has a local file inclusion vulnerability. This vulnerability applies to all users of org.http4s.server.staticcontent.FileService,… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.