CVE-2026-69205
Received Received - Intake

HTTP Header Parsing Flaw in Http4s Enables Request Smuggling

Vulnerability report for CVE-2026-69205, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: GitHub, Inc.

Description

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HeaderP.parse uses a case-sensitive substring test for the Transfer-Encoding value and decodes header bytes with the platform default charset. Values such as Chunked are not recognized, values such as notchunked are incorrectly accepted, and Unicode case folding can turn a Kelvin-sign byte sequence into a match when UTF-8 is used. Intermediaries that apply RFC-compliant token and charset rules can therefore disagree with Ember’s Content-Length or zero-length framing, enabling TE.CL or TE.0 request smuggling, access-control bypass, cross-user request hijacking, and cache poisoning on the server path. Response smuggling through an ember-client gateway requires a malicious or compromised upstream. This issue is fixed in versions 0.23.35 and 1.0.0-M47.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
ember headerp to 1.0.0-M47 (exc)
ember headerp From 0.23.35 (inc)
ember headerp From 1.0.0-M47 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-444 The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Http4s involves improper handling of the Transfer-Encoding header. The parser used a case-sensitive substring test to check for 'chunked' encoding, allowing malformed values like 'Chunked' or 'notchunked' to be accepted. This created a request smuggling risk where an RFC-compliant proxy might use chunked encoding while the parser fell back to Content-Length framing, leading to TE.CL or TE.0 request smuggling attacks.

Detection Guidance

Detecting this vulnerability requires checking for http4s versions prior to 0.23.35 or 1.0.0-M47. Inspect your http4s dependencies in build files (e.g., build.sbt, pom.xml) for versions below these thresholds. Use commands like 'sbt dependencyTree' or 'mvn dependency:tree' to list dependencies. Additionally, monitor HTTP request smuggling attempts by analyzing network traffic for malformed Transfer-Encoding headers such as 'Chunked' or 'notchunked'.

Impact Analysis

This vulnerability can enable several attacks including request smuggling, access-control bypass, cross-user request hijacking, and cache poisoning on the server path. It may also allow response smuggling if http4s is used as a gateway. The attack requires an unauthenticated remote attacker and a compliant intermediary that treats Transfer-Encoding case-insensitively.

Compliance Impact

This vulnerability enables HTTP request smuggling, which can lead to cache poisoning, cross-user request hijacking, and access-control bypasses. Such attacks may violate GDPR's data integrity and security requirements (Article 32) by exposing or altering user data. For HIPAA, request smuggling could compromise protected health information confidentiality or integrity during transmission, violating the Security Rule's safeguards.

Mitigation Strategies

Upgrade http4s to version 0.23.35 or 1.0.0-M47 or later. If upgrading is not immediately possible, implement a workaround by normalizing the Transfer-Encoding header to lowercase 'chunked' at your proxy or gateway. Ensure your intermediary strictly validates Transfer-Encoding headers per RFC 9112 §6.1. Avoid using platform-dependent charset decoding for headers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-69205. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart