org.http4s:http4s-client_3
Maven3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.http4s:http4s-client_3page 1 of 1
- CVE-2021-41084HIGHCVSS 8.7EG 8.7✓ Fixed in 0.23.42021-09-21
vulnerable: 0.23.0, 0.23.1, 0.23.2, 0.23.3
http4s is an open source scala interface for HTTP. In affected versions http4s is vulnerable to response-splitting or request-splitting attacks when untrusted user input is used to create any of the following fields: Header names (`Header.…
- CVE-2026-69214MEDIUMCVSS 6.8EG 6.8✓ Fixed in 1.0.0-M472026-09-15
vulnerable: 1.0.0-M22 ... 1.0.0-M46 (24 versions)
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware stores a response cookie’s Domain attribute without checking that it domain-matches the host that supplied the cookie or rejec…
- CVE-2026-69215MEDIUMCVSS 6.8EG 6.8✓ Fixed in 0.23.352026-09-15
vulnerable: 0.22.0 ... 0.23.9 (58 versions)
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware uses unanchored substring checks instead of RFC 6265 domain and path matching when deciding whether to attach a stored cookie. A…
Check whether org.http4s:http4s-client_3 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.http4s:http4s-client_3 CVEs against the assets you own.
Start Free Scan →