CVE-2026-69217
Received Received - Intake

HTTP/1.1 Request Smuggling in Http4s Ember

Vulnerability report for CVE-2026-69217, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: GitHub, Inc.

Description

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/1.1 parser accepts differing duplicate Content-Length headers and uses the last value instead of rejecting the message. When an Ember server is behind a keep-alive intermediary that selects a different occurrence, an unauthenticated attacker can create CL.CL request smuggling that bypasses front-end controls, captures a later user’s headers, or poisons a cache. The shared client parser can also misframe responses from a malicious or compromised upstream when the client acts as a proxy for multiple downstream consumers. This issue is fixed in versions 0.23.35 and 1.0.0-M47.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ember ember 0.23.35
ember ember 1.0.0-m47

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-444 The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Http4s's Ember HTTP/1.1 parser in versions before 0.23.35 and 1.0.0-M47 incorrectly accepts duplicate Content-Length headers with differing values. Instead of rejecting such requests per RFC 9112, it uses the last value, enabling request smuggling attacks when behind a keep-alive intermediary. The client parser also misframes responses from malicious upstreams when acting as a proxy.

Detection Guidance

To detect this vulnerability, inspect HTTP requests for duplicate Content-Length headers with differing values. Use tools like Wireshark or tcpdump to capture traffic and filter for malformed headers. Check server logs for 400 Bad Request responses when duplicate Content-Length headers are present. Test with curl commands sending requests containing duplicate Content-Length headers to observe server behavior.

Impact Analysis

An unauthenticated attacker could bypass front-end security controls, hijack another user's session by capturing their headers, or poison caches by smuggling malicious requests. This occurs because the server misinterprets the request structure due to conflicting Content-Length headers.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating confidentiality and integrity requirements in GDPR and HIPAA. Compromised systems may fail compliance audits due to inadequate request validation and security controls.

Mitigation Strategies

Immediately upgrade http4s to version 0.23.35 or 1.0.0-M47 or later. If upgrading is not possible, configure a strictly-conformant intermediary proxy that rejects requests with duplicate Content-Length headers. Monitor network traffic for signs of request smuggling attempts. Review and update firewall rules to block suspicious requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-69217. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart