CVE-2025-59822
- EPSS 0.06%
- Veröffentlicht 23.09.2025 19:15:42
- Zuletzt bearbeitet 08.10.2025 17:35:04
Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section. This vulnerability could enable attacker...
CVE-2023-22465
- EPSS 0.07%
- Veröffentlicht 04.01.2023 16:15:09
- Zuletzt bearbeitet 21.11.2024 07:44:51
Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the `User-Agent` and `Server` header parsers are susceptible to a fatal error on certain inputs. In http4s, mo...
CVE-2021-41084
- EPSS 0.45%
- Veröffentlicht 21.09.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:25:25
http4s is an open source scala interface for HTTP. In affected versions http4s is vulnerable to response-splitting or request-splitting attacks when untrusted user input is used to create any of the following fields: Header names (`Header.name`å), He...
CVE-2021-39185
- EPSS 0.17%
- Veröffentlicht 01.09.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:18:49
Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0.22.2, 0.23.0, 0.23.1, and 1.0.0-M1 through 1.0.0-M24, the default CORS configuration is vulnerable to an origin reflection attack...
CVE-2021-32643
- EPSS 0.32%
- Veröffentlicht 27.05.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:26
Http4s is a Scala interface for HTTP services. `StaticFile.fromUrl` can leak the presence of a directory on a server when the `URL` scheme is not `file://`, and the URL points to a fetchable resource under its scheme and authority. The function retur...
CVE-2021-21294
- EPSS 0.41%
- Veröffentlicht 02.02.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:47:57
Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Http4s before versions 0.21.17, 0.22.0-M2, and 1.0.0-M14 have a vulnerability which can lead to a denial-of-service. Blaze-core, a library underlying http4s-blaze...
CVE-2020-5280
- EPSS 0.85%
- Veröffentlicht 25.03.2020 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:33:49
http4s before versions 0.18.26, 0.20.20, and 0.21.2 has a local file inclusion vulnerability. This vulnerability applies to all users of org.http4s.server.staticcontent.FileService, org.http4s.server.staticcontent.ResourceService and org.http4s.serve...