VendorsTypelevelhttp4sall versions
Vulnerabilities

Typelevel http4s

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2021-39185
Default CORS config allows any origin with credentials
Published 2021-09-01 · Modified
9.1EPSS 0.006
CVE-2021-41084
Response Splitting from unsanitized headers in http4s
Published 2021-09-21 · Modified
8.7EPSS 0.012
CVE-2020-5280
Local file inclusion vulnerability in http4s
Published 2020-03-25 · Modified
7.6EPSS 0.070
CVE-2021-21294
Unbounded connection acceptance in http4s-blaze-server
Published 2021-02-02 · Modified
7.5EPSS 0.021
CVE-2023-22465
Http4s has fatal error parsing User-Agent and Server headers
Published 2023-01-04 · Modified
7.5EPSS 0.008
CVE-2025-59822
Http4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section
Published 2025-09-23 · Analyzed
7.5EPSS 0.004
CVE-2021-32643
StaticFile.fromUrl can leak presence of a directory
Published 2021-05-27 · Modified
5.8EPSS 0.014