Impact
Http4s is a Scala interface for HTTP services. The Ember HTTP/1.1 parser prior to 0.23.35 and 1.0.0‑M47 accepts different duplicate Content‑Length headers and uses the last value instead of rejecting the request. An unauthenticated attacker that can control a keep‑alive intermediary can select a different header occurrence to smuggle a request, allowing the attacker to bypass front‑end controls, capture a later user’s headers, or poison a cache. The shared client parser can also misframe responses from a malicious or compromised upstream when the client acts as a proxy for multiple downstream consumers, potentially leading to data leakage or misrouting.
Affected Systems
The affected software is the Http4s library for Scala, specifically the Ember server implementation. It affects all releases earlier than 0.23.35 and 1.0.0‑M47. Any project that includes Http4s Ember before these versions is susceptible.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is 0.00499 and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet. Based on the description, the likely attack vector is an unauthenticated attacker who can manipulate request headers behind a keep‑alive proxy to influence the last Content‑Length value processed by Ember. By smuggling the request, the attacker can bypass front‑end controls, extract hidden headers, or poison caches, potentially leading to data disclosure or denial of service.
OpenCVE Enrichment