Vulnerabilidades em http4s

31 resultados
Análise Vexday

O http4s apresenta 8 vulnerabilidades catalogadas, com 1 de severidade crítica, porém nenhuma sob exploração ativa conhecida. A fraqueza dominante é controle inadequado de recursos (CWE-400), típica de problemas de negação de serviço. Sem publicações recentes (últimos 90 dias), o risco atual é contido, mas a criticidade isolada merece monitoramento de patches disponíveis.

CVE-2020-5280HIGHLocal file inclusion vulnerability in http4sEPSS 7.0%CVE-2021-21294HIGHUnbounded connection acceptance in http4s-blaze-serverEPSS 2.1%CVE-2021-21293HIGHUnbounded connection acceptance leads to file handle exhaustionEPSS 2.1%CVE-2021-32643MEDIUMStaticFile.fromUrl can leak presence of a directoryEPSS 1.4%CVE-2021-41084HIGHResponse Splitting from unsanitized headers in http4sEPSS 1.2%CVE-2023-22465HIGHHttp4s has fatal error parsing User-Agent and Server headersEPSS 0.8%CVE-2026-69208HIGHHttp4s: DigestAuth nonce map grows unboundedEPSS 0.8%CVE-2026-69201MEDIUMHttp4s: ResourceService and Webjar Service path escape via percent-encoded separatorsEPSS 0.8%CVE-2026-69218HIGHHttp4s Ember HTTP/2: unbounded continuation frame accumulationEPSS 0.6%CVE-2026-69210HIGHHttp4s: WebSocket decoder accepts negative length, causing infinite decode loopEPSS 0.6%CVE-2026-69209HIGHHttp4s: WebSocket decoder accepts unbounded message sizesEPSS 0.6%CVE-2026-69213HIGHHttp4s Ember HTTP/2: unbounded outbound frame queueEPSS 0.6%CVE-2026-73493HIGHhttp4s-blaze-server: Unbounded WebSocket message aggregationEPSS 0.6%CVE-2026-88975HIGHHttp4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZEEPSS 0.6%CVE-2026-69203HIGHHttp4s Ember HTTP/2: does not enforce SETTINGS_MAX_CONCURRENT_STREAMSEPSS 0.6%CVE-2026-69202HIGHHttp4s Ember HTTP/2: unbounded inbound body bufferingEPSS 0.6%CVE-2026-73494HIGHblaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parserEPSS 0.6%CVE-2021-39185CRITICALDefault CORS config allows any origin with credentialsEPSS 0.6%CVE-2026-69204CRITICALHttp4s: Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)EPSS 0.6%CVE-2026-54556HIGHHttp4s: HTTP/2 Denial of Service with Ember BackendEPSS 0.5%