CVE-2026-69216
Received Received - Intake

HTTP Request Smuggling in Http4s

Vulnerability report for CVE-2026-69216, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: GitHub, Inc.

Description

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s chunk decoder trims the chunk-size token and accepts leading plus or minus signs instead of requiring one or more hexadecimal digits followed by the required CRLF. When an intermediary forwards chunked data without re-encoding and interprets malformed chunk boundaries differently, an unauthenticated attacker can create TE.TE request smuggling that bypasses intermediary controls, poisons caches, or hijacks the request queue. The same response-path leniency can enable response smuggling against an ember-client used as a gateway when the upstream is malicious or compromised. This issue is fixed in versions 0.23.35 and 1.0.0-M47.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ember chunk_decoder to 0.23.35 (inc)
ember chunk_decoder to 1.0.0-M47 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-444 The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-69216 is a vulnerability in the Http4s library's Ember chunk decoder. It allows malformed HTTP chunked transfer encoding requests to bypass security controls due to lenient parsing. The decoder incorrectly accepts leading or trailing whitespace and optional plus or minus signs in chunk sizes, violating RFC9112 standards which require strict hexadecimal digits. This inconsistency enables HTTP request smuggling (TE.TE) attacks where attackers can poison caches or hijack request queues.

Detection Guidance

To detect this vulnerability, monitor HTTP traffic for malformed chunked transfer encoding requests. Check for chunk sizes with leading/trailing whitespace, plus/minus signs, or non-hexadecimal characters. Use tools like Wireshark or tcpdump to capture and analyze HTTP requests for violations of RFC9112 standards. Inspect proxy or gateway logs for inconsistent chunk parsing between upstream and downstream systems.

Impact Analysis

This vulnerability can impact you by allowing unauthenticated attackers to bypass security controls, poison caches, or hijack request queues through HTTP request smuggling. If you use affected versions of Http4s as a server or client, malicious upstream systems or intermediaries could exploit this to manipulate requests or responses. The impact depends on your deployment scenario and whether intermediaries process chunked data.

Compliance Impact

This vulnerability primarily enables HTTP request smuggling and cache poisoning, which could lead to unauthorized data access or modification. For GDPR, this may violate principles of data integrity and confidentiality. For HIPAA, it could expose protected health information to unauthorized parties. Compliance may be impacted if systems fail to protect data in transit as required by these regulations.

Mitigation Strategies

Immediately upgrade http4s to versions 0.23.35 or 1.0.0-M47 or later. If upgrading is not possible, configure intermediaries (proxies, gateways) to enforce strict RFC9112-compliant chunked transfer encoding validation. Reject requests with malformed chunk sizes or missing CRLF delimiters. Monitor network traffic for signs of request smuggling attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-69216. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart