CVE-2026-69211
Received Received - Intake

ResponseCookie Header Injection in Http4s

Vulnerability report for CVE-2026-69211, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: GitHub, Inc.

Description

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResponseCookie.render writes attacker-influenced name, content, domain, path, and extension values without neutralizing semicolons or control characters. An application that constructs a ResponseCookie from unvalidated input can therefore emit injected cookie attributes such as Domain, Path, or SameSite, widening cookie scope or weakening protections, and control characters may enable header splitting on permissive backends. The patch strips control characters from all five fields and strips semicolons from name, content, domain, and path while retaining the extension delimiter behavior. This issue is fixed in versions 0.23.35 and 1.0.0-M47.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
http4s http4s to 0.23.35 (exc)
http4s http4s to 1.0.0-M47 (exc)
http4s http4s 0.23.35
http4s http4s 1.0.0-M47

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1286 The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.
CWE-113 The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the http4s library, where the ResponseCookie.render function writes cookie fields (name, content, domain, path, extension) without proper sanitization. Attackers can inject semicolons or control characters into these fields, leading to cookie attribute manipulation or header splitting attacks.

Detection Guidance

To detect this vulnerability, inspect your http4s application for ResponseCookie usage with unvalidated input. Check for cookie fields containing semicolons or control characters in Set-Cookie headers. Use tools like curl to inspect headers: curl -I http://yourserver.com. Monitor for unexpected cookie attributes like Domain or Path modifications.

Impact Analysis

An attacker could widen cookie scope by injecting Domain or Path attributes, weaken SameSite protections, or perform header splitting if the backend is permissive. This requires no privileges or user interaction and can be exploited remotely.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling unauthorized cookie attribute manipulation. Attackers could inject attributes like Domain or Path to widen cookie scope, potentially accessing sensitive data across subdomains or weakening SameSite protections. CR/LF injection could also enable header splitting, risking data exposure or session hijacking. These risks may violate data protection requirements for secure session handling and cross-domain access controls.

Mitigation Strategies

Upgrade http4s to patched versions: 0.23.35 for Scala 2.12/3 or 1.0.0-M47 for Scala 2.13/3. Validate cookie field values against RFC6265 before constructing ResponseCookie objects. Strip control characters and semicolons from name, content, domain, and path fields.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-69211. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart