Vulnerabilidades em http4s
31 resultadosAnálise Vexday
O http4s apresenta 8 vulnerabilidades catalogadas, com 1 de severidade crítica, porém nenhuma sob exploração ativa conhecida. A fraqueza dominante é controle inadequado de recursos (CWE-400), típica de problemas de negação de serviço. Sem publicações recentes (últimos 90 dias), o risco atual é contido, mas a criticidade isolada merece monitoramento de patches disponíveis.
CVE-2026-69215MEDIUMHttp4s: CookieJar middleware matches by substring, leaking cookies cross-originEPSS 0.5%CVE-2026-69217HIGHHttp4s: Ember Server accepts duplicate Content-Length headersEPSS 0.5%CVE-2026-73495HIGHblaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)EPSS 0.5%CVE-2026-69205HIGHHttp4s: Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling)EPSS 0.5%CVE-2026-69214MEDIUMHttp4s: CookieJar middleware accepts arbitrary Set-Cookie domainEPSS 0.4%CVE-2026-69206MEDIUMHttp4s: DigestAuth allows replay of captured requestsEPSS 0.4%CVE-2025-59822MEDIUMHttp4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sectionEPSS 0.4%CVE-2026-69216MEDIUMHttp4s: Ember chunk parser lenience (TE.TE request smuggling)EPSS 0.4%CVE-2026-69211MEDIUMHttp4s: Set-Cookie rendering does not escape attribute delimitersEPSS 0.3%CVE-2026-61741CRITICALhttp4s-scala-xml has an XML External Entity (XXE) processing issueEPSS 0.3%CVE-2026-69212MEDIUMHttp4s: FollowRedirect middleware leaks credentials over https->http same-authority redirectEPSS 0.3%