Http4s 是用于 HTTP 服务的 Scala 接口。在版本 0.23.35 和 1.0.0-M47 之前, 方法在对攻击者可控的 、 、 、 以及扩展字段值进行输出时,未对分号( )或控制字符进行中和(转义或过滤)处理。因此,如果应用程序基于未经验证的用户输入构建 ,就可能注入额外的 Cookie 属性(如 、 或 ),从而导致 Cookie 作用域被扩大或安全保护被削弱;此外,控制字符在较为宽松的底层后端上可能引发 HTTP 头注入(Header Splitting)。该补丁已从上述五个字段中移除所有控制字
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-69204 | 9.2 CRITICAL | Http4s: Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggl |
| CVE-2026-69217 | 8.7 HIGH | Http4s: Ember Server accepts duplicate Content-Length headers |
| CVE-2026-69205 | 8.7 HIGH | Http4s: Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling) |
| CVE-2026-88975 | 7.5 HIGH | Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME |
| CVE-2026-69202 | 7.5 HIGH | Http4s Ember HTTP/2: unbounded inbound body buffering |
| CVE-2026-69218 | 7.5 HIGH | Http4s Ember HTTP/2: unbounded continuation frame accumulation |
| CVE-2026-69210 | 7.5 HIGH | Http4s: WebSocket decoder accepts negative length, causing infinite decode loop |
| CVE-2026-69213 | 7.5 HIGH | Http4s Ember HTTP/2: unbounded outbound frame queue |
| CVE-2026-69203 | 7.5 HIGH | Http4s Ember HTTP/2: does not enforce SETTINGS_MAX_CONCURRENT_STREAMS |
| CVE-2026-69209 | 7.5 HIGH | Http4s: WebSocket decoder accepts unbounded message sizes |
| CVE-2026-69208 | 7.5 HIGH | Http4s: DigestAuth nonce map grows unbounded |
| CVE-2026-69214 | 6.8 MEDIUM | Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain |
| CVE-2026-69215 | 6.8 MEDIUM | Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin |
| CVE-2026-69201 | 5.9 MEDIUM | Http4s: ResourceService and Webjar Service path escape via percent-encoded separators |
| CVE-2026-69212 | 5.9 MEDIUM | Http4s: FollowRedirect middleware leaks credentials over https->http same-authority redire |
| CVE-2026-69206 | 5.9 MEDIUM | Http4s: DigestAuth allows replay of captured requests |
| CVE-2026-69216 | 5.4 MEDIUM | Http4s: Ember chunk parser lenience (TE.TE request smuggling) |
No comments yet