Vulnerabilidades em http4s
10 resultadosAnálise Vexday
O http4s apresenta 8 vulnerabilidades catalogadas, com 1 de severidade crítica, porém nenhuma sob exploração ativa conhecida. A fraqueza dominante é controle inadequado de recursos (CWE-400), típica de problemas de negação de serviço. Sem publicações recentes (últimos 90 dias), o risco atual é contido, mas a criticidade isolada merece monitoramento de patches disponíveis.
CVE-2020-5280HIGHLocal file inclusion vulnerability in http4sEPSS 7.0%CVE-2021-21294HIGHUnbounded connection acceptance in http4s-blaze-serverEPSS 2.1%CVE-2021-21293HIGHUnbounded connection acceptance leads to file handle exhaustionEPSS 2.1%CVE-2021-32643MEDIUMStaticFile.fromUrl can leak presence of a directoryEPSS 1.4%CVE-2021-41084HIGHResponse Splitting from unsanitized headers in http4sEPSS 1.2%CVE-2023-22465HIGHHttp4s has fatal error parsing User-Agent and Server headersEPSS 0.8%CVE-2021-39185CRITICALDefault CORS config allows any origin with credentialsEPSS 0.6%CVE-2025-59822MEDIUMHttp4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sectionEPSS 0.3%CVE-2026-73493HIGHhttp4s-blaze-server: Unbounded WebSocket message aggregationEPSS —CVE-2026-73495HIGHblaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)EPSS —