PT-2026-92380 · Http4S · Http4S

CVE-2026-69211

·

Published

2026-09-15

·

Updated

2026-09-16

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Http4s versions prior to 0.23.35 Http4s versions prior to 1.0.0-M47
Description The ResponseCookie.render() function fails to neutralize semicolons or control characters when writing name, content, domain, path, and extension values. If an application uses unvalidated input to construct a ResponseCookie, an attacker can inject cookie attributes like Domain, Path, or SameSite. This can widen the cookie scope or weaken security protections. Additionally, the use of control characters may allow header splitting on permissive backends, a technique where an attacker inserts newline characters to inject additional HTTP headers into the response.
Recommendations Update to version 0.23.35 or later. Update to version 1.0.0-M47 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-69211
GHSA-7QH7-RGHH-698H

Affected Products

Http4S