CVE-2023-22465
Estado: ModificadaMedia (5.3)—
Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the `User-Agent` and `Server` header parsers are susceptible to a fatal error on certain inputs. In http4s, modeled headers are lazily parsed, so this only applies to services that explicitly request these typed headers. Fixes are released in 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38. As a workaround, use the weakly typed header interface.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.84%
- Percentil entre todas las CVEs puntuadas: 57
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
- CWE-20
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-22465",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-22465",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-03-10T21:02:19.525721Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "http4s",
"product": "http4s",
"versions": [
{
"status": "affected",
"version": ">= 0.1.0, < 0.21.34"
},
{
"status": "affected",
"version": ">= 0.22.0, < 0.22.15"
},
{
"status": "affected",
"version": ">= 0.23.0, < 0.23.17"
},
{
"status": "affected",
"version": ">= 1.0.0-M1, < 1.0.0-M38"
}
]
}
]
}
],
"published": "2023-01-04T16:15:09.323",
"references": [
{
"url": "https://github.com/http4s/http4s/security/advisories/GHSA-54w6-vxfh-fw7f",
"tags": [
"Exploit",
"Mitigation",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/http4s/http4s/security/advisories/GHSA-54w6-vxfh-fw7f",
"tags": [
"Exploit",
"Mitigation",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the `User-Agent` and `Server` header parsers are susceptible to a fatal error on certain inputs. In http4s, modeled headers are lazily parsed, so this only applies to services that explicitly request these typed headers. Fixes are released in 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38. As a workaround, use the weakly typed header interface."
},
{
"lang": "es",
"value": "Http4s es una interfaz de Scala para servicios HTTP. A partir de la versión 0.1.0 y anteriores a las versiones 0.21.34, 0.22.15, 0.23.17 y 1.0.0-M38, los analizadores de encabezado `User-Agent` y `Server` son susceptibles a un error fatal en ciertas entradas. En http4s, los encabezados modelados se analizan de forma diferida, por lo que esto solo se aplica a los servicios que solicitan explícitamente estos encabezados escritos. Las correcciones se publicaron en 0.21.34, 0.22.15, 0.23.17 y 1.0.0-M38. Como workaround, utilice la interfaz de encabezado con tipos débiles."
}
],
"lastModified": "2026-06-17T05:35:30.800",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:typelevel:http4s:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "185B0C49-B7B4-436A-9577-3276FCE1181F",
"versionEndExcluding": "0.21.34",
"versionStartIncluding": "0.1.0"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AF811C59-F1EA-49A0-A335-D395AC17EC76",
"versionEndExcluding": "0.22.15",
"versionStartIncluding": "0.22.0"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "79816BBF-3E40-4E20-8138-281DA5CF65E9",
"versionEndExcluding": "0.23.17",
"versionStartIncluding": "0.23.0"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "65C497F9-281C-4565-BD36-B6B4D7E6F8BD"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone10:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6FCFC3E5-7530-4AAA-A2C7-36DC307B613B"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone11:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D03CBFE3-0B31-4D7C-BC5D-61DCD3C2C486"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone12:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "76F8BC53-544C-4285-8D9B-CB91AD080048"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone13:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "778947CA-20BA-469F-87E1-97D8713ACC75"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone14:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F5B02828-1E40-49BE-8367-10296625C696"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone15:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A569F32F-3C8C-4F8F-B0BC-6ADC993596A9"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone16:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "525DBF4B-F574-459D-9CE2-6AF597ABAE10"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone17:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FD05B15E-1E4F-43EA-B21A-3B96A77814D6"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone18:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "65C79F52-F05F-4F0A-AC27-393197B9EF00"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone19:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A426B4C0-643A-492F-B7FB-725549F613F6"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D95E231C-3D13-45FC-AF9A-CB8CF1FFC983"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone20:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CF973F58-0AC7-4B58-A2CF-654133CE7F1A"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone21:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "35C40331-C96C-477C-B6BD-D5506E612DA8"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone22:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "615BC827-3E0F-4C1E-8FD2-B59FF31F2D49"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone23:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FDFB35FD-4D08-4895-B1B6-FC03BCB3EB22"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone24:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "97F74D04-031E-47D4-BA57-DBE9C74CE256"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone25:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2FDC2E12-DE86-4A82-BD2F-C18F715CA673"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone26:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C1C18467-5FD0-4DCC-8B75-979C03BFF1C4"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone27:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6724B3CF-A393-469B-BA80-CED8AB98358A"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone28:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "804EF10D-46A9-49C0-B1C4-74B832115662"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone29:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2DE365D6-17C4-4E82-8F2B-1DA18CC8382F"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DE093D65-1B3A-4A4A-BC76-05DEF9529712"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone30:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "078E27D3-AD80-44E8-A97C-328AEB4E2929"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone31:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "548DB4B7-872D-4A7E-9DA7-D0BF15BDE969"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone32:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "07037A73-F463-4F8B-8F8B-AF513B31DA21"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone33:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "801D2731-BD6D-4CD9-B69F-75DC1A0FE3CD"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone34:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AA2C32F3-93A3-4A2F-9A9A-DC06056EDC81"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone35:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "59C3ECBA-47D1-4A9B-8193-8033BC27CC37"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone36:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9B7AF9D4-4548-4D25-84BC-54C525179342"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone37:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0D884D1D-F74D-406F-A363-C008097C997E"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DC3CA618-148D-4F97-9913-316DDDD97838"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "02FA538C-9D8A-49D5-8268-1A2C3E96B89B"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D18A3ABC-5C47-45BF-978C-5BB17787DCFA"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1CE1CF51-E61A-418A-AB22-9D7A6D690BAA"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "29A70AAA-B77A-4291-A700-C910362DB8D4"
},
{
"criteria": "cpe:2.3:a:typelevel:http4s:1.0.0:milestone9:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F8F3C38-57AB-4CBC-8959-7FF51CBA7907"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}