Description
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/1.1 parser accepts differing duplicate Content-Length headers and uses the last value instead of rejecting the message. When an Ember server is behind a keep-alive intermediary that selects a different occurrence, an unauthenticated attacker can create CL.CL request smuggling that bypasses front-end controls, captures a later user’s headers, or poisons a cache. The shared client parser can also misframe responses from a malicious or compromised upstream when the client acts as a proxy for multiple downstream consumers. This issue is fixed in versions 0.23.35 and 1.0.0-M47.
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Request Smuggling
Action: Patch
AI Analysis

Impact

Http4s is a Scala interface for HTTP services. The Ember HTTP/1.1 parser prior to 0.23.35 and 1.0.0‑M47 accepts different duplicate Content‑Length headers and uses the last value instead of rejecting the request. An unauthenticated attacker that can control a keep‑alive intermediary can select a different header occurrence to smuggle a request, allowing the attacker to bypass front‑end controls, capture a later user’s headers, or poison a cache. The shared client parser can also misframe responses from a malicious or compromised upstream when the client acts as a proxy for multiple downstream consumers, potentially leading to data leakage or misrouting.

Affected Systems

The affected software is the Http4s library for Scala, specifically the Ember server implementation. It affects all releases earlier than 0.23.35 and 1.0.0‑M47. Any project that includes Http4s Ember before these versions is susceptible.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score is 0.00499 and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet. Based on the description, the likely attack vector is an unauthenticated attacker who can manipulate request headers behind a keep‑alive proxy to influence the last Content‑Length value processed by Ember. By smuggling the request, the attacker can bypass front‑end controls, extract hidden headers, or poison caches, potentially leading to data disclosure or denial of service.

Generated by OpenCVE AI on September 20, 2026 at 12:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Http4s library to version 0.23.35 or newer, including 1.0.0‑M47 where the issue is fixed.
  • If upgrading is not immediately possible, configure any upstream keep‑alive intermediaries to reject requests that contain duplicate Content‑Length headers or to ensure only a single header is forwarded to Ember.
  • Implement network filtering or firewall rules that block or flag HTTP requests containing duplicate Content‑Length headers as a temporary protection, and monitor traffic for smuggling attempts.

Generated by OpenCVE AI on September 20, 2026 at 12:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Http4s
Http4s http4s
Vendors & Products Http4s
Http4s http4s

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/1.1 parser accepts differing duplicate Content-Length headers and uses the last value instead of rejecting the message. When an Ember server is behind a keep-alive intermediary that selects a different occurrence, an unauthenticated attacker can create CL.CL request smuggling that bypasses front-end controls, captures a later user’s headers, or poisons a cache. The shared client parser can also misframe responses from a malicious or compromised upstream when the client acts as a proxy for multiple downstream consumers. This issue is fixed in versions 0.23.35 and 1.0.0-M47.
Title Http4s: Ember Server accepts duplicate Content-Length headers
Weaknesses CWE-444
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T13:52:40.263Z

Reserved: 2026-08-03T16:57:50.125Z

Link: CVE-2026-69217

cve-icon Vulnrichment

Updated: 2026-09-16T13:52:34.271Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:17:41.120

Modified: 2026-09-16T20:39:16.610

Link: CVE-2026-69217

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T12:45:17Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')