Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)
🔗 CVE IDs covered (1)
📋 Description
Summary
Ember's HTTP/1.1 request parser does not reject a message that carries both a
Transfer-Encoding and a Content-Length header. RFC 9112 §6.1 requires a
server to treat such a message as a framing error and close the connection.
An intermediary that follows the RFC's CL-strip-and-forward path (or that
prioritises Content-Length) will frame the body differently from Ember,
enabling HTTP request smuggling (CL.TE).
Impact
Server
Request smuggling when ember-server is an origin behind an intermediary that
forwards both headers over a keep-alive backend connection and frames by
Content-Length while Ember frames by chunked:
- Front-end security bypass: the smuggled request reaches paths the intermediary's ACL/auth layer would have blocked, with attacker-chosen method and headers.
- Cross-user request hijack: a dangling smuggled prefix concatenates with the next victim's request on the shared backend socket, capturing its headers.
- Cache poisoning: the smuggled response is associated with the next request key in a caching proxy.
Client
ember-client shares the same parser on the response path. An upstream that sends both headers can desync a pooled client connection. This requires a malicious or compromised upstream.
Preconditions
- Unauthenticated remote attacker (server)
- ember-server as origin behind a keep-alive intermediary
- Intermediary forwards a request carrying both
Transfer-EncodingandContent-Length(RFC says it MAY reject; many forward) and frames byContent-Length - Malicious or compromised upstream (client)
Workarounds
- Intermediary strictly rejects requests carrying both
Transfer-EncodingandContent-Length - Intermediary buffers and re-encodes request bodies
- Disable backend keep-alive between the intermediary and Ember
🎯 Affected products5
- maven/org.http4s:http4s-ember-core_2.12:<= 0.23.34
- maven/org.http4s:http4s-ember-core_2.13:<= 0.23.34
- maven/org.http4s:http4s-ember-core_3:<= 0.23.34
- maven/org.http4s:http4s-ember-core_2.13:>= 1.0.0-M1, <= 1.0.0-M46
- maven/org.http4s:http4s-ember-core_3:>= 1.0.0-M1, <= 1.0.0-M46
🔗 References (5)
- https://github.com/http4s/http4s/security/advisories/GHSA-8h4c-x2wg-6xp8
- https://github.com/http4s/http4s/commit/9feaf8677951a52af906ae9664ff6f0543d9d810
- https://github.com/http4s/http4s/releases/tag/v0.23.35
- https://github.com/http4s/http4s/releases/tag/v1.0.0-M47
- https://github.com/advisories/GHSA-8h4c-x2wg-6xp8