PT-2026-92407 · Http4S · Http4S

CVE-2026-69216

·

Published

2026-09-15

·

Updated

2026-09-16

CVSS v3.1

5.4

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Http4s versions prior to 0.23.35 Http4s versions prior to 1.0.0-M47
Description Ember's chunk decoder parses the chunk-size token leniently by trimming whitespace and accepting leading plus or minus signs, which deviates from the requirement for one or more hexadecimal digits followed by a CRLF. This leniency allows an unauthenticated attacker to perform TE.TE request smuggling when an intermediary forwards chunked data without re-encoding and interprets malformed chunk boundaries differently. This can lead to bypassing intermediary security controls, cache poisoning, or hijacking the request queue. Additionally, the same leniency in the response path can enable response smuggling against an ember-client used as a gateway if the upstream server is malicious or compromised.
Recommendations Update to version 0.23.35. Update to version 1.0.0-M47. Configure the intermediary to strictly reject malformed chunk sizes. Configure the intermediary to buffer and re-encode request bodies.

Exploit

Fix

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-69216
GHSA-JRPM-956J-96JG

Affected Products

Http4S