CVEs we hold for Http4s
Records whose assigning authority named Http4s as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-88975Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZEhttp4s CVE-2026-73495blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)http4s blaze CVE-2026-73494blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parserhttp4s blaze; org.http4s blaze-http_2.13… CVE-2026-73493http4s-blaze-server: Unbounded WebSocket message aggregationhttp4s blaze CVE-2026-69218Http4s Ember HTTP/2: unbounded continuation frame accumulationhttp4s CVE-2026-69217Http4s: Ember Server accepts duplicate Content-Length headershttp4s CVE-2026-69216Http4s: Ember chunk parser lenience (TE.TE request smuggling)http4s CVE-2026-69215Http4s: CookieJar middleware matches by substring, leaking cookies cross-originhttp4s CVE-2026-69214Http4s: CookieJar middleware accepts arbitrary Set-Cookie domainhttp4s CVE-2026-69213Http4s Ember HTTP/2: unbounded outbound frame queuehttp4s CVE-2026-69212Http4s: FollowRedirect middleware leaks credentials over https->http same-authority redirecthttp4s CVE-2026-69211Http4s: Set-Cookie rendering does not escape attribute delimitershttp4s CVE-2026-69210Http4s: WebSocket decoder accepts negative length, causing infinite decode loophttp4s CVE-2026-69209Http4s: WebSocket decoder accepts unbounded message sizeshttp4s CVE-2026-69206Http4s: DigestAuth allows replay of captured requestshttp4s CVE-2026-69205Http4s: Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling)http4s CVE-2026-69204Http4s: Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)http4s CVE-2026-69203Http4s Ember HTTP/2: does not enforce SETTINGS_MAX_CONCURRENT_STREAMShttp4s CVE-2026-69202Http4s Ember HTTP/2: unbounded inbound body bufferinghttp4s CVE-2026-69201Http4s: ResourceService and Webjar Service path escape via percent-encoded separatorshttp4s CVE-2026-54556Http4s: HTTP/2 Denial of Service with Ember Backendhttp4s; org.http4s http4s-ember-core_2.12… CVE-2025-59822Http4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sectionhttp4s CVE-2023-22465Http4s has fatal error parsing User-Agent and Server headershttp4s CVE-2021-41084Response Splitting from unsanitized headers in http4shttp4s CVE-2021-39185Default CORS config allows any origin with credentialshttp4s CVE-2021-32643StaticFile.fromUrl can leak presence of a directoryhttp4s CVE-2021-21294Unbounded connection acceptance in http4s-blaze-serverhttp4s CVE-2021-21293Unbounded connection acceptance leads to file handle exhaustionhttp4s blaze 30 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.