org.http4s:http4s-ember-core_3
Maven11 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.http4s:http4s-ember-core_3page 1 of 1
- CVE-2025-59822HIGHCVSS 7.5EG 7.5✓ Fixed in 1.0.0-M452025-09-23
vulnerable: 1.0.0-M22 ... 1.0.0-M44 (22 versions)
Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section. This vulnerability could enab…
- CVE-2026-54556HIGHCVSS 8.2EG 8.2✓ Fixed in 1.0.0-M472026-08-26
vulnerable: 1.0.0-M22 ... 1.0.0-M46 (24 versions)
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, an unauthenticated HTTP/2 peer can cause an out-of-memory denial of service in the Ember backend with HTTP/2 enabled. The Hpack wrapper in ember-core/shared/src…
- CVE-2026-69202HIGHCVSS 7.5EG 7.5✓ Fixed in 0.23.352026-09-15
vulnerable: 0.22.0 ... 0.23.9 (58 versions)
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/2 flow-control window is replenished according to bytes received from the network rather than bytes consumed by the application, while each strea…
- CVE-2026-69203HIGHCVSS 7.5EG 7.5✓ Fixed in 0.23.352026-09-15
vulnerable: 0.22.0 ... 0.23.9 (58 versions)
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, An Ember server with HTTP/2 enabled through withHttp2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS for peer-created streams. One unauthenticated connection …
- CVE-2026-69204CRITICALCVSS 9.2EG 9.2✓ Fixed in 0.23.352026-09-15
vulnerable: 0.22.0 ... 0.23.9 (58 versions)
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/1.1 does not reject messages containing both Transfer-Encoding and Content-Length, so an intermediary and Ember can select different body framing rul…
- CVE-2026-69205HIGHCVSS 8.7EG 8.7✓ Fixed in 0.23.352026-09-15
vulnerable: 0.22.0 ... 0.23.9 (58 versions)
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HeaderP.parse uses a case-sensitive substring test for the Transfer-Encoding value and decodes header bytes with the platform default charset. Values …
- CVE-2026-69206MEDIUMCVSS 5.9EG 5.9✓ Fixed in 0.23.352026-09-15
vulnerable: 0.22.0 ... 0.23.9 (58 versions)
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, DigestAuth replay protection records lastNc plus one instead of the highest nonce-count value it has accepted. When a legitimate client sends noncontiguous nc v…
- CVE-2026-69213HIGHCVSS 7.5EG 7.5✓ Fixed in 0.23.352026-09-15
vulnerable: 0.22.0 ... 0.23.9 (58 versions)
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames through one unbounded queue consumed by writeLoop. When the peer stops reading, an unauthenticated HTTP/2 client can con…
- CVE-2026-69216MEDIUMCVSS 5.4EG 5.4✓ Fixed in 0.23.352026-09-15
vulnerable: 0.22.0 ... 0.23.9 (58 versions)
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s chunk decoder trims the chunk-size token and accepts leading plus or minus signs instead of requiring one or more hexadecimal digits followed by the r…
- CVE-2026-69218HIGHCVSS 7.5EG 7.5✓ Fixed in 0.23.352026-09-15
vulnerable: 0.22.0 ... 0.23.9 (58 versions)
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, When Ember receives an HTTP/2 HEADERS or PUSH_PROMISE frame without END_HEADERS, H2Connection buffers the header block and subsequent CONTINUATION fragments wit…
- CVE-2026-88975HIGHCVSS 7.5EG 7.5✓ Fixed in 0.23.372026-09-15
vulnerable: 0.22.0 ... 0.23.9 (60 versions)
Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’s 24-bit declared length but waits to buffer the entire payload before comparing it with SETTINGS_MAX_FRAME_SIZE. An…
Check whether org.http4s:http4s-ember-core_3 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.http4s:http4s-ember-core_3 CVEs against the assets you own.
Start Free Scan →