Impact
The Ember HTTP/1.1 implementation in Http4s does not reject messages that contain both Transfer-Encoding and Content-Length headers. This flaw enables request smuggling, allowing an unauthenticated attacker to send a second request that bypasses intermediary access controls, poison caches, or merge a victim request with attacker‑controlled data. Because the shared response parser can desynchronize an ember‑client connection when a malicious upstream sends both headers, the vulnerability permits arbitrary manipulation of request boundaries, effectively undermining confidentiality and integrity of the traffic. The weakness is classified as CWE‑444 request smuggling.
Affected Systems
All releases of Http4s Ember prior to 0.23.35 in the 0.x series and prior to 1.0.0‑M47 in the 1.x series are affected. The vulnerability pertains to the Ember HTTP/1.1 component of the Http4s Scala library.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.2, indicating high severity. The EPSS score is < 1%, indicating a very low but non‑zero probability of exploitation, and the issue is not listed in CISA KEV. However, the combination of a long‑lived flaw with the ability to smuggle requests makes exploitation likely in environments that route traffic through keep‑alive intermediaries. An attacker who can inject forged HTTP requests is likely able to bypass upstream access controls, manipulate cached responses, and potentially execute arbitrary requests on behalf of the victim. The attack vector is over the network, requiring no authentication, and the flaw can be exploited remotely by sending specially crafted requests to a vulnerable Ember server.
OpenCVE Enrichment
Github GHSA