VYPR

Maven package

org.http4s/http4s-ember-core_3

pkg:maven/org.http4s/http4s-ember-core_3

Vulnerabilities (2)

  • CVE-2026-54556HigAug 26, 2026
    affected < 0.23.35fixed 0.23.35

    Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, an unauthenticated HTTP/2 peer can cause an out-of-memory denial of service in the Ember backend with HTTP/2 enabled. The Hpack wrapper in ember-core/shared/src/main/scala/org/http4s/ember/core/h2/Hpac

  • CVE-2025-59822HigSep 23, 2025
    affected < 0.23.31fixed 0.23.31

    Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section. This vulnerability could enable attackers to bypass front-end servers