๐Ÿ” CVE Alert

CVE-2026-69204

UNKNOWN 0.0

Http4s: Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/1.1 does not reject messages containing both Transfer-Encoding and Content-Length, so an intermediary and Ember can select different body framing rules. When ember-server is behind a keep-alive intermediary that forwards both headers and frames by Content-Length, an unauthenticated attacker can smuggle a second request, bypass intermediary access controls, poison caches, or cause a victim request to be joined to an attacker-controlled prefix. The shared response parser can also desynchronize an ember-client connection when a malicious or compromised upstream sends both headers. This issue is fixed in versions 0.23.35 and 1.0.0-M47.

CWE CWE-444
Vendor http4s
Product http4s
Published Sep 15, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for http4s http4s

Be the first to know when new unknown vulnerabilities affecting http4s http4s are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

http4s / http4s
< 0.23.35 >= 1.0.0-M1, < 1.0.0-M47

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/http4s/http4s/security/advisories/GHSA-8h4c-x2wg-6xp8 github.com: https://github.com/http4s/http4s/commit/9feaf8677951a52af906ae9664ff6f0543d9d810 github.com: https://github.com/http4s/http4s/releases/tag/v0.23.35 github.com: https://github.com/http4s/http4s/releases/tag/v1.0.0-M47