Medium severity6.8NVD Advisory· Published Sep 15, 2026
CVE-2026-69215
CVE-2026-69215
Description
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware uses unanchored substring checks instead of RFC 6265 domain and path matching when deciding whether to attach a stored cookie. A cookie for example.com can consequently be sent to an attacker-controlled hostname such as evilexample.com when an application using the same jar makes an attacker-influenced outbound request. This exposes session or authentication cookies and can enable hijacking of the application’s outbound sessions. This issue is fixed in versions 0.23.35 and 1.0.0-M47.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.http4s:http4s-client_2.12Maven | < 0.23.35 | 0.23.35 |
org.http4s:http4s-client_2.13Maven | < 0.23.35 | 0.23.35 |
org.http4s:http4s-client_3Maven | < 0.23.35 | 0.23.35 |
org.http4s:http4s-client_2.13Maven | >= 1.0.0-M1, < 1.0.0-M47 | 1.0.0-M47 |
org.http4s:http4s-client_3Maven | >= 1.0.0-M1, < 1.0.0-M47 | 1.0.0-M47 |
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-grh8-3p95-f9rrghsaADVISORY
- github.com/http4s/http4s/commit/c0a37f38d5ee2a568ba57bd9da62f8d79b8b1fccnvdWEB
- github.com/http4s/http4s/releases/tag/v0.23.35nvdWEB
- github.com/http4s/http4s/releases/tag/v1.0.0-M47nvdWEB
- github.com/http4s/http4s/security/advisories/GHSA-grh8-3p95-f9rrnvdWEB
News mentions
0No linked articles in our index yet.