Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the `User-Agent` and `Server` header parsers are susceptible to a fatal error on certain inputs. In http4s, modeled headers are lazily parsed, so this only applies to services that explicitly request these typed headers. Fixes are released in 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38. As a workaround, use the weakly typed header interface.
References
Link | Resource |
---|---|
https://github.com/http4s/http4s/security/advisories/GHSA-54w6-vxfh-fw7f | Exploit Mitigation Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2023-01-04 08:15
Updated : 2023-01-10 18:23
NVD link : CVE-2023-22465
Mitre link : CVE-2023-22465
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
typelevel
- http4s