PT-2025-39209 · Http4S · Http4S

Sebastianosrt

·

Published

2025-09-23

·

Updated

2025-10-08

·

CVE-2025-59822

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Http4s versions 1.0.0-M1 through 1.0.0-M44 Http4s versions prior to 0.23.31
Description Http4s is susceptible to HTTP Request Smuggling because of incorrect handling of the HTTP trailer section. This can allow attackers to circumvent front-end server security measures, conduct attacks on current users, and corrupt web caches. Exploitation requires the web application to be deployed behind a reverse proxy that forwards trailer headers.
Recommendations Update to Http4s version 1.0.0-M45 or later. Update to Http4s version 0.23.31 or later.

Exploit

Fix

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

CVE-2025-59822
GHSA-WCWH-7GFW-5WRR

Affected Products

Http4S