Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8h4c-x2wg-6xp8 | Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling) |
Tue, 15 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/1.1 does not reject messages containing both Transfer-Encoding and Content-Length, so an intermediary and Ember can select different body framing rules. When ember-server is behind a keep-alive intermediary that forwards both headers and frames by Content-Length, an unauthenticated attacker can smuggle a second request, bypass intermediary access controls, poison caches, or cause a victim request to be joined to an attacker-controlled prefix. The shared response parser can also desynchronize an ember-client connection when a malicious or compromised upstream sends both headers. This issue is fixed in versions 0.23.35 and 1.0.0-M47. | |
| Title | Http4s: Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling) | |
| Weaknesses | CWE-444 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T19:00:49.739Z
Reserved: 2026-08-03T16:57:50.124Z
Link: CVE-2026-69204
Updated: 2026-09-15T19:00:46.496Z
Status : Received
Published: 2026-09-15T19:17:37.580
Modified: 2026-09-15T19:17:37.580
Link: CVE-2026-69204
No data.
OpenCVE Enrichment
No data.
Github GHSA