PT-2025-39209 · Http4S · Http4S
Sebastianosrt
·
Published
2025-09-23
·
Updated
2025-10-08
·
CVE-2025-59822
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Http4s versions 1.0.0-M1 through 1.0.0-M44
Http4s versions prior to 0.23.31
Description
Http4s is susceptible to HTTP Request Smuggling because of incorrect handling of the HTTP trailer section. This can allow attackers to circumvent front-end server security measures, conduct attacks on current users, and corrupt web caches. Exploitation requires the web application to be deployed behind a reverse proxy that forwards trailer headers.
Recommendations
Update to Http4s version 1.0.0-M45 or later.
Update to Http4s version 0.23.31 or later.
Exploit
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Http4S