CVE-2026-69214
Received Received - Intake

Cookie Domain Spoofing in Http4s

Vulnerability report for CVE-2026-69214, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: GitHub, Inc.

Description

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware stores a response cookie’s Domain attribute without checking that it domain-matches the host that supplied the cookie or rejecting public suffixes. A malicious or compromised server contacted through the same CookieJar can plant a cookie for another domain, and the jar later sends that cookie to the victim domain, enabling session fixation or overwriting security-sensitive cookies. The patch validates the Set-Cookie domain against the response origin, although public-suffix rejection remains unimplemented. This issue is fixed in versions 0.23.35 and 1.0.0-M47.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
http4s http4s to 0.23.35 (exc)
http4s http4s to 1.0.0-M47 (exc)
http4s http4s 0.23.35
http4s http4s 1.0.0-M47

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-565 The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.
CWE-384 Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Http4s is a Scala library for HTTP services. This vulnerability involves the CookieJar client middleware storing cookies without validating the Domain attribute against the response host. A malicious server can set a cookie for another domain, which the CookieJar later sends to the victim domain. This enables session fixation or overwrites security-sensitive cookies.

Detection Guidance

To detect this vulnerability, check if your system uses http4s versions prior to 0.23.35 or 1.0.0-M47. Inspect the CookieJar middleware for improper cookie domain handling. Review server logs for unexpected cookie domain mismatches or unauthorized cookie storage.

Impact Analysis

An attacker could hijack user sessions by fixing session IDs or overwrite cookies like authentication tokens. This could grant unauthorized access to accounts or bypass security controls. Applications using vulnerable http4s versions with untrusted servers are at risk.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Session hijacking or cookie manipulation may result in data breaches, triggering compliance violations and potential penalties.

Mitigation Strategies

Upgrade http4s to version 0.23.35 or 1.0.0-M47 or later. Avoid sharing a single CookieJar across trusted and untrusted targets. Validate cookie domains manually if using older versions. Monitor for suspicious cookie modifications or session fixation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-69214. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart