Description
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/1.1 does not reject messages containing both Transfer-Encoding and Content-Length, so an intermediary and Ember can select different body framing rules. When ember-server is behind a keep-alive intermediary that forwards both headers and frames by Content-Length, an unauthenticated attacker can smuggle a second request, bypass intermediary access controls, poison caches, or cause a victim request to be joined to an attacker-controlled prefix. The shared response parser can also desynchronize an ember-client connection when a malicious or compromised upstream sends both headers. This issue is fixed in versions 0.23.35 and 1.0.0-M47.
Published: 2026-09-15
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote request smuggling enabling arbitrary request execution
Action: Immediate Patch
AI Analysis

Impact

The Ember HTTP/1.1 implementation in Http4s does not reject messages that contain both Transfer-Encoding and Content-Length headers. This flaw enables request smuggling, allowing an unauthenticated attacker to send a second request that bypasses intermediary access controls, poison caches, or merge a victim request with attacker‑controlled data. Because the shared response parser can desynchronize an ember‑client connection when a malicious upstream sends both headers, the vulnerability permits arbitrary manipulation of request boundaries, effectively undermining confidentiality and integrity of the traffic. The weakness is classified as CWE‑444 request smuggling.

Affected Systems

All releases of Http4s Ember prior to 0.23.35 in the 0.x series and prior to 1.0.0‑M47 in the 1.x series are affected. The vulnerability pertains to the Ember HTTP/1.1 component of the Http4s Scala library.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.2, indicating high severity. The EPSS score is < 1%, indicating a very low but non‑zero probability of exploitation, and the issue is not listed in CISA KEV. However, the combination of a long‑lived flaw with the ability to smuggle requests makes exploitation likely in environments that route traffic through keep‑alive intermediaries. An attacker who can inject forged HTTP requests is likely able to bypass upstream access controls, manipulate cached responses, and potentially execute arbitrary requests on behalf of the victim. The attack vector is over the network, requiring no authentication, and the flaw can be exploited remotely by sending specially crafted requests to a vulnerable Ember server.

Generated by OpenCVE AI on September 20, 2026 at 13:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ember to version 0.23.35 or later in the 0.x line, or to version 1.0.0-M47 or later in the 1.x line.
  • If upgrading is not immediately possible, configure any intervening proxies or load balancers to reject requests that contain both Transfer-Encoding and Content-Length headers, or to strip one of them.
  • Disable or tightly restrict keep‑alive support for upstream clients that could forward both headers when communicating with an Ember server.

Generated by OpenCVE AI on September 20, 2026 at 13:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8h4c-x2wg-6xp8 Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)
History

Tue, 15 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Http4s
Http4s http4s
Vendors & Products Http4s
Http4s http4s

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/1.1 does not reject messages containing both Transfer-Encoding and Content-Length, so an intermediary and Ember can select different body framing rules. When ember-server is behind a keep-alive intermediary that forwards both headers and frames by Content-Length, an unauthenticated attacker can smuggle a second request, bypass intermediary access controls, poison caches, or cause a victim request to be joined to an attacker-controlled prefix. The shared response parser can also desynchronize an ember-client connection when a malicious or compromised upstream sends both headers. This issue is fixed in versions 0.23.35 and 1.0.0-M47.
Title Http4s: Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)
Weaknesses CWE-444
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T19:00:49.739Z

Reserved: 2026-08-03T16:57:50.124Z

Link: CVE-2026-69204

cve-icon Vulnrichment

Updated: 2026-09-15T19:00:46.496Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T19:17:37.580

Modified: 2026-09-16T20:39:16.610

Link: CVE-2026-69204

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T13:15:14Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')