VendorsTypelevelhttp4s1.0.0
Vulnerabilities

Typelevel http4s 1.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2021-39185
Default CORS config allows any origin with credentials
Published 2021-09-01 · Modified
9.1EPSS 0.006
CVE-2021-41084
Response Splitting from unsanitized headers in http4s
Published 2021-09-21 · Modified
8.7EPSS 0.012
CVE-2023-22465
Http4s has fatal error parsing User-Agent and Server headers
Published 2023-01-04 · Modified
7.5EPSS 0.008
CVE-2025-59822
Http4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section
Published 2025-09-23 · Analyzed
7.5EPSS 0.004
CVE-2021-32643
StaticFile.fromUrl can leak presence of a directory
Published 2021-05-27 · Modified
5.8EPSS 0.014