VYPR

Maven package

org.http4s/http4s-server_2.11

pkg:maven/org.http4s/http4s-server_2.11

Vulnerabilities (2)

  • CVE-2021-41084Sep 21, 2021
    affected <= 0.21.28

    http4s is an open source scala interface for HTTP. In affected versions http4s is vulnerable to response-splitting or request-splitting attacks when untrusted user input is used to create any of the following fields: Header names (`Header.name`å), Header values (`Header.value`),

  • CVE-2021-39185Sep 1, 2021
    affected >= 0

    Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0.22.2, 0.23.0, 0.23.1, and 1.0.0-M1 through 1.0.0-M24, the default CORS configuration is vulnerable to an origin reflection attack. The middleware is also susce