← Back

CVE-2025-59822

nvd nist
Published: Sep 23, 2025Modified: Oct 8, 2025

JSON object

Loading...
6.3
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security-advisories@github.com (Secondary)

Description

Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section. This vulnerability could enable attackers to bypass front-end servers security controls, launch targeted attacks against active users, and poison web caches. A pre-requisite for exploitation involves the web application being deployed behind a reverse-proxy that forwards trailer headers. This issue has been patched in versions 1.0.0-M45 and 0.23.31.

Affected (45)

Products: Typelevel: Http4s
1 product
Http4s
Configuration A
45 vulnerable
Vulnerable SoftwareAffected Versions
Typelevel
Before 0.23.31
Version 1.0.0 milestone10
Version 1.0.0 milestone11
Version 1.0.0 milestone12
Version 1.0.0 milestone13
Version 1.0.0 milestone14
Version 1.0.0 milestone15
Version 1.0.0 milestone16
Version 1.0.0 milestone17
Version 1.0.0 milestone18
Version 1.0.0 milestone19
Version 1.0.0 milestone1
Version 1.0.0 milestone20
Version 1.0.0 milestone21
Version 1.0.0 milestone22
Version 1.0.0 milestone23
Version 1.0.0 milestone24
Version 1.0.0 milestone25
Version 1.0.0 milestone26
Version 1.0.0 milestone27
Version 1.0.0 milestone28
Version 1.0.0 milestone29
Version 1.0.0 milestone2
Version 1.0.0 milestone30
Version 1.0.0 milestone31
Version 1.0.0 milestone32
Version 1.0.0 milestone33
Version 1.0.0 milestone34
Version 1.0.0 milestone35
Version 1.0.0 milestone36
Version 1.0.0 milestone37
Version 1.0.0 milestone38
Version 1.0.0 milestone39
Version 1.0.0 milestone3
Version 1.0.0 milestone40
Version 1.0.0 milestone41
Version 1.0.0 milestone42
Version 1.0.0 milestone43
Version 1.0.0 milestone44
Version 1.0.0 milestone4
Version 1.0.0 milestone5
Version 1.0.0 milestone6
Version 1.0.0 milestone7
Version 1.0.0 milestone8
Version 1.0.0 milestone9

References (3)

Source: security-advisories@github.com
ExploitVendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitVendor Advisory

Timeline

No history available yet.