Http4s Vulnerability in Ember HTTP/1.1 Affects HTTP Services
CVE-2026-69204

9.2CRITICAL

Key Information:

Vendor

Http4s

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-69204?

Prior to versions 0.23.35 and 1.0.0-M47, Ember HTTP/1.1 permits messages that include both Transfer-Encoding and Content-Length headers, leading to severe security risks. This can allow an unauthenticated attacker to exploit intermediary servers, allowing them to bypass access controls, poison caches, or merge malicious requests with valid ones. The vulnerability also leads to potential desynchronization issues with ember-client connections when affected by compromised upstream servers. The issue has been addressed and patched in the specified versions.

Affected Version(s)

http4s < 0.23.35 < 0.23.35

http4s >= 1.0.0-M1, < 1.0.0-M47 < 1.0.0-M1, 1.0.0-M47

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.