Http4s 是用于 HTTP 服务的 Scala 接口。在 0.23.35 和 1.0.0-M47 之前,Ember 的 HTTP/2 流控窗口是根据从网络接收的字节数进行补充的,而不是根据应用程序实际消耗的字节数进行补充;同时,每个流在一个无界通道中存储 DATA 数据。因此,恶意对端可以以快于慢速或未排空的应用程序消耗速度的方式发送请求体,导致在配置了 的 ember-server 或 ember-client 中,载荷会在堆内存中不断累积。该补丁通过限制每个流的 H2Connection 请求体通道大小,使
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-69204 | 9.2 CRITICAL | Http4s: Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggl |
| CVE-2026-69217 | 8.7 HIGH | Http4s: Ember Server accepts duplicate Content-Length headers |
| CVE-2026-69205 | 8.7 HIGH | Http4s: Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling) |
| CVE-2026-69208 | 7.5 HIGH | Http4s: DigestAuth nonce map grows unbounded |
| CVE-2026-88975 | 7.5 HIGH | Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME |
| CVE-2026-69218 | 7.5 HIGH | Http4s Ember HTTP/2: unbounded continuation frame accumulation |
| CVE-2026-69210 | 7.5 HIGH | Http4s: WebSocket decoder accepts negative length, causing infinite decode loop |
| CVE-2026-69213 | 7.5 HIGH | Http4s Ember HTTP/2: unbounded outbound frame queue |
| CVE-2026-69203 | 7.5 HIGH | Http4s Ember HTTP/2: does not enforce SETTINGS_MAX_CONCURRENT_STREAMS |
| CVE-2026-69209 | 7.5 HIGH | Http4s: WebSocket decoder accepts unbounded message sizes |
| CVE-2026-69214 | 6.8 MEDIUM | Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain |
| CVE-2026-69215 | 6.8 MEDIUM | Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin |
| CVE-2026-69201 | 5.9 MEDIUM | Http4s: ResourceService and Webjar Service path escape via percent-encoded separators |
| CVE-2026-69212 | 5.9 MEDIUM | Http4s: FollowRedirect middleware leaks credentials over https->http same-authority redire |
| CVE-2026-69206 | 5.9 MEDIUM | Http4s: DigestAuth allows replay of captured requests |
| CVE-2026-69216 | 5.4 MEDIUM | Http4s: Ember chunk parser lenience (TE.TE request smuggling) |
| CVE-2026-69211 | 4.8 MEDIUM | Http4s: Set-Cookie rendering does not escape attribute delimiters |
No comments yet