Maven package
org.http4s/http4s-ember-core_3
pkg:maven/org.http4s/http4s-ember-core_3
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-54556 | hig | — | < 0.23.35 | 0.23.35 | Aug 26, 2026 | ### Summary http4s 0.23.x and 1.0 servers running ember with http2 enabled are vulnerable to a denial of service attack using a HPACK bomb vulnerability recently disclosed as affecting other http2 servers. ### Impact Denial of Service: - Affects any http4s server running the e | |
| CVE-2025-59822 | Hig | 7.5 | < 0.23.31 | 0.23.31 | Sep 23, 2025 | Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section. This vulnerability could enable attackers to bypass front-end servers |
- affected < 0.23.35fixed 0.23.35
### Summary http4s 0.23.x and 1.0 servers running ember with http2 enabled are vulnerable to a denial of service attack using a HPACK bomb vulnerability recently disclosed as affecting other http2 servers. ### Impact Denial of Service: - Affects any http4s server running the e
- affected < 0.23.31fixed 0.23.31
Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section. This vulnerability could enable attackers to bypass front-end servers