PT-2026-92380 · Http4S · Http4S
CVE-2026-69211
·
Published
2026-09-15
·
Updated
2026-09-16
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Http4s versions prior to 0.23.35
Http4s versions prior to 1.0.0-M47
Description
The
ResponseCookie.render() function fails to neutralize semicolons or control characters when writing name, content, domain, path, and extension values. If an application uses unvalidated input to construct a ResponseCookie, an attacker can inject cookie attributes like Domain, Path, or SameSite. This can widen the cookie scope or weaken security protections. Additionally, the use of control characters may allow header splitting on permissive backends, a technique where an attacker inserts newline characters to inject additional HTTP headers into the response.Recommendations
Update to version 0.23.35 or later.
Update to version 1.0.0-M47 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Http4S