CVE-2026-69215
Received Received - Intake

Cookie Handling Flaw in Http4s Exposes Session Data

Vulnerability report for CVE-2026-69215, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: GitHub, Inc.

Description

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware uses unanchored substring checks instead of RFC 6265 domain and path matching when deciding whether to attach a stored cookie. A cookie for example.com can consequently be sent to an attacker-controlled hostname such as evilexample.com when an application using the same jar makes an attacker-influenced outbound request. This exposes session or authentication cookies and can enable hijacking of the application’s outbound sessions. This issue is fixed in versions 0.23.35 and 1.0.0-M47.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
http4s http4s to 0.23.35 (exc)
http4s http4s to 1.0.0-M47 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-565 The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.
CWE-1275 The SameSite attribute for sensitive cookies is not set, or an insecure value is used.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the CookieJar middleware in Http4s, a Scala HTTP library. It uses unanchored substring checks instead of proper RFC 6265 domain and path matching when attaching stored cookies to requests. This allows cookies intended for a domain like example.com to be sent to attacker-controlled hosts like evilexample.com, potentially exposing session or authentication cookies.

Detection Guidance

To detect this vulnerability, inspect your Scala applications using http4s versions prior to 0.23.35 or 1.0.0-M47. Check for CookieJar middleware usage in HTTP client configurations. Review outbound requests to domains containing trusted domains as substrings (e.g., evilexample.com).

Commands: grep -r "CookieJar" /path/to/project || find . -name "*.scala" -exec grep -l "CookieJar" {} \;. Check dependency versions in build.sbt or project files for http4s versions below 0.23.35 or 1.0.0-M47.

Impact Analysis

An attacker could intercept session or authentication cookies by tricking an application into making outbound requests to attacker-controlled domains. This could lead to session hijacking, unauthorized access to user accounts, or data breaches. The impact is primarily on confidentiality as cookies are exposed to unintended recipients.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements under GDPR and HIPAA. Exposure of session or authentication cookies may result in data breaches, triggering compliance violations, potential fines, and reputational damage for organizations handling protected user data.

Mitigation Strategies

Upgrade http4s to versions 0.23.35 or 1.0.0-M47 or later. Avoid using CookieJar with untrusted URLs. Use separate CookieJars for each trusted origin to isolate cookies.

If upgrading is not possible, disable CookieJar middleware or implement strict domain/path validation checks manually before sending requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-69215. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart