Http4s Vulnerability in Ember HTTP/1.1 Affects HTTP Services
CVE-2026-69204
9.2CRITICAL
What is CVE-2026-69204?
Prior to versions 0.23.35 and 1.0.0-M47, Ember HTTP/1.1 permits messages that include both Transfer-Encoding and Content-Length headers, leading to severe security risks. This can allow an unauthenticated attacker to exploit intermediary servers, allowing them to bypass access controls, poison caches, or merge malicious requests with valid ones. The vulnerability also leads to potential desynchronization issues with ember-client connections when affected by compromised upstream servers. The issue has been addressed and patched in the specified versions.
Affected Version(s)
http4s < 0.23.35 < 0.23.35
http4s >= 1.0.0-M1, < 1.0.0-M47 < 1.0.0-M1, 1.0.0-M47
