VYPR

Maven package

org.http4s/http4s-ember-core_3

pkg:maven/org.http4s/http4s-ember-core_3

Vulnerabilities (2)

  • CVE-2026-54556higAug 26, 2026
    affected < 0.23.35fixed 0.23.35

    ### Summary http4s 0.23.x and 1.0 servers running ember with http2 enabled are vulnerable to a denial of service attack using a HPACK bomb vulnerability recently disclosed as affecting other http2 servers. ### Impact Denial of Service: - Affects any http4s server running the e

  • CVE-2025-59822HigSep 23, 2025
    affected < 0.23.31fixed 0.23.31

    Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section. This vulnerability could enable attackers to bypass front-end servers