Impact
ResponseCookie.render creates Set‑Cookie headers by concatenating cookie name, value, domain, path, and extensions without neutralizing semicolons or control characters. This allows anyone who can influence any of those fields to inject additional cookie attributes such as Domain, Path, or SameSite, and to embed control characters that may split HTTP headers on permissive backends. The injected attributes widen cookie scope or weaken SameSite enforcement, while header splitting can alter the structure of outgoing responses. The issue does not grant direct remote code execution but can alter browser behavior and backend processing.
Affected Systems
The Http4s Scala HTTP library is affected. All releases earlier than 0.23.35 and 1.0.0‑M47 contain the flaw. Applications that instantiate ResponseCookie with data derived from untrusted sources while using these vulnerable versions are at risk.
Risk and Exploitability
The CVSS score is 4.8, indicating moderate severity, and the EPSS score is less than 1%, pointing to a very low likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires the application to accept external data that is used to populate cookie fields; an attacker who controls that input can inject cookie attributes or header‑splitting characters. The impact is confined to cookie handling and header injection and could undermine SameSite protections or alter subsequent requests on permissive backends.
OpenCVE Enrichment