PT-2026-92407 · Http4S · Http4S
CVE-2026-69216
·
Published
2026-09-15
·
Updated
2026-09-16
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Http4s versions prior to 0.23.35
Http4s versions prior to 1.0.0-M47
Description
Ember's chunk decoder parses the
chunk-size token leniently by trimming whitespace and accepting leading plus or minus signs, which deviates from the requirement for one or more hexadecimal digits followed by a CRLF. This leniency allows an unauthenticated attacker to perform TE.TE request smuggling when an intermediary forwards chunked data without re-encoding and interprets malformed chunk boundaries differently. This can lead to bypassing intermediary security controls, cache poisoning, or hijacking the request queue. Additionally, the same leniency in the response path can enable response smuggling against an ember-client used as a gateway if the upstream server is malicious or compromised.Recommendations
Update to version 0.23.35.
Update to version 1.0.0-M47.
Configure the intermediary to strictly reject malformed chunk sizes.
Configure the intermediary to buffer and re-encode request bodies.
Exploit
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Http4S