Typelevel

Http4s

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.06%
  • Veröffentlicht 23.09.2025 19:15:42
  • Zuletzt bearbeitet 08.10.2025 17:35:04

Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section. This vulnerability could enable attacker...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 04.01.2023 16:15:09
  • Zuletzt bearbeitet 21.11.2024 07:44:51

Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the `User-Agent` and `Server` header parsers are susceptible to a fatal error on certain inputs. In http4s, mo...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 21.09.2021 18:15:07
  • Zuletzt bearbeitet 21.11.2024 06:25:25

http4s is an open source scala interface for HTTP. In affected versions http4s is vulnerable to response-splitting or request-splitting attacks when untrusted user input is used to create any of the following fields: Header names (`Header.name`å), He...

  • EPSS 0.17%
  • Veröffentlicht 01.09.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:18:49

Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0.22.2, 0.23.0, 0.23.1, and 1.0.0-M1 through 1.0.0-M24, the default CORS configuration is vulnerable to an origin reflection attack...

  • EPSS 0.32%
  • Veröffentlicht 27.05.2021 18:15:07
  • Zuletzt bearbeitet 21.11.2024 06:07:26

Http4s is a Scala interface for HTTP services. `StaticFile.fromUrl` can leak the presence of a directory on a server when the `URL` scheme is not `file://`, and the URL points to a fetchable resource under its scheme and authority. The function retur...

  • EPSS 0.41%
  • Veröffentlicht 02.02.2021 22:15:12
  • Zuletzt bearbeitet 21.11.2024 05:47:57

Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Http4s before versions 0.21.17, 0.22.0-M2, and 1.0.0-M14 have a vulnerability which can lead to a denial-of-service. Blaze-core, a library underlying http4s-blaze...

  • EPSS 0.85%
  • Veröffentlicht 25.03.2020 18:15:14
  • Zuletzt bearbeitet 21.11.2024 05:33:49

http4s before versions 0.18.26, 0.20.20, and 0.21.2 has a local file inclusion vulnerability. This vulnerability applies to all users of org.http4s.server.staticcontent.FileService, org.http4s.server.staticcontent.ResourceService and org.http4s.serve...