CVE-2026-69201
Received Received - Intake

Path Traversal in Http4s Scala HTTP Library

Vulnerability report for CVE-2026-69201, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: GitHub, Inc.

Description

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResourceService and WebjarService decode each URL path segment but reject only segments exactly equal to an empty string, a dot, or two dots. A request containing percent-encoded slash or backslash separators can turn an accepted segment into a parent-directory traversal after decoding, allowing access to classpath or WebJar resources outside the configured base when a directory-backed classpath is served and the backend preserves the encoded separator. The patch rejects decoded segments containing slash or backslash in ResourceService and WebjarService, and applies the same guard to the non-exploitable FileService for consistency. This issue is fixed in versions 0.23.35 and 1.0.0-M47.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
http4s http4s-server to 0.23.35 (exc)
http4s http4s-server to 1.0.0-M47 (exc)
http4s http4s-server 0.23.35
http4s http4s-server 1.0.0-M47

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the http4s-server library and involves path escape attacks in ResourceService and WebjarService. Attackers can use percent-encoded separators like %2F (forward slash) or %5C (backslash) in URLs to bypass security filters and access restricted resources outside the intended base directory. The issue occurs when the application serves resources from a directory and the backend forwards encoded separators without normalization.

Detection Guidance

To detect this vulnerability, inspect your http4s-server application logs for requests containing percent-encoded path separators like %2F (forward slash) or %5C (backslash) in URL paths. Check if these requests return 400 Bad Request responses after the patch, as the fix should reject such encoded separators.

Impact Analysis

An attacker could exploit this to access sensitive classpath or WebJar resources that should be restricted. This could lead to unauthorized disclosure of files or data. The impact is higher on Windows systems and requires specific conditions like non-root base paths and directory-backed classpath serving.

Compliance Impact

This vulnerability could potentially violate compliance requirements under GDPR and HIPAA by enabling unauthorized access to sensitive resources. GDPR requires protecting personal data, while HIPAA mandates securing protected health information. The flaw allows attackers to bypass access controls and retrieve restricted classpath or WebJar resources, which may contain sensitive data. Unauthorized disclosure of such resources could lead to regulatory violations and data breaches.

Mitigation Strategies
  • Upgrade http4s-server to version 0.23.35 or 1.0.0-M47 or later to apply the patch.
  • If upgrading is not immediately possible, deploy the application as a fat jar to avoid filesystem directory exposure.
  • Use a reverse proxy (e.g., Nginx, Apache) to normalize URLs and block encoded path separators before they reach the application.
  • Avoid serving resources from filesystem directories on the classpath if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-69201. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart