CVE-2026-69204
Received Received - Intake

HTTP Request Smuggling in Http4s Ember Server

Vulnerability report for CVE-2026-69204, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: GitHub, Inc.

Description

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/1.1 does not reject messages containing both Transfer-Encoding and Content-Length, so an intermediary and Ember can select different body framing rules. When ember-server is behind a keep-alive intermediary that forwards both headers and frames by Content-Length, an unauthenticated attacker can smuggle a second request, bypass intermediary access controls, poison caches, or cause a victim request to be joined to an attacker-controlled prefix. The shared response parser can also desynchronize an ember-client connection when a malicious or compromised upstream sends both headers. This issue is fixed in versions 0.23.35 and 1.0.0-M47.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ember ember_http to 0.23.35 (inc)
ember ember_http to 1.0.0-m47 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-444 The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves HTTP request smuggling in the Http4s library. When both Transfer-Encoding and Content-Length headers are present in a request, the server and intermediary may interpret the request body differently. This allows an attacker to smuggle a second request, bypass access controls, poison caches, or manipulate responses.

Detection Guidance

Detecting this vulnerability requires monitoring for HTTP requests containing both Transfer-Encoding and Content-Length headers. Use network traffic analysis tools like tcpdump or Wireshark to inspect HTTP headers for dual-header requests. For web servers or proxies, enable verbose logging to capture malformed requests. Example commands: tcpdump -i any -A -s 0 'tcp port 80 and (((ip[2:2] - ((ip[0]&0xf)<<2)) - ((tcp[12]&0xf0)>>2)) != 0)' or check web server logs for 400 Bad Request responses indicating header parsing errors.

Impact Analysis

If you use Http4s versions before 0.23.35 or 1.0.0-M47, an attacker could bypass security controls, hijack user sessions, poison caches, or cause desynchronization of client connections. This requires the attacker to control or compromise an upstream server or intermediary.

Compliance Impact

This vulnerability primarily enables HTTP request smuggling, which could lead to unauthorized access, data breaches, or manipulation of requests and responses. For GDPR, this could result in unauthorized data exposure or processing, violating principles of data protection and user consent. Under HIPAA, it may compromise the integrity and confidentiality of protected health information by allowing unauthorized interception or alteration of requests containing sensitive data.

Mitigation Strategies

Immediately upgrade http4s to version 0.23.35 or 1.0.0-M47 or later. If upgrading is not possible, configure intermediaries (proxies, load balancers) to reject requests with both Transfer-Encoding and Content-Length headers. Disable keep-alive connections between intermediaries and backends or implement buffering and re-encoding of request bodies to normalize headers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-69204. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart