org.http4s:http4s-server_2.11
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.http4s:http4s-server_2.11page 1 of 1
- CVE-2021-39185CRITICALCVSS 9.1EG 9.12021-09-01
vulnerable: 0.10.0 ... 0.9.3 (220 versions)
Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0.22.2, 0.23.0, 0.23.1, and 1.0.0-M1 through 1.0.0-M24, the default CORS configuration is vulnerable to an origin reflec…
- CVE-2021-41084HIGHCVSS 8.7EG 8.72021-09-21
vulnerable: 0.10.0 ... 0.9.3 (220 versions)
http4s is an open source scala interface for HTTP. In affected versions http4s is vulnerable to response-splitting or request-splitting attacks when untrusted user input is used to create any of the following fields: Header names (`Header.…
Check whether org.http4s:http4s-server_2.11 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.http4s:http4s-server_2.11 CVEs against the assets you own.
Start Free Scan →