CVE-2025-59822

MEDIUM EPSS 26.8%
Published Sep 23, 20259mo ago · Modified Jun 17, 20262w ago
6.3 CVSS 4.0
Medium
Find Similar
Published Sep 23, 2025 9mo ago
Last Modified Jun 17, 2026 2w ago

Description

Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section. This vulnerability could enable attackers to bypass front-end servers security controls, launch targeted attacks against active users, and poison web caches. A pre-requisite for exploitation involves the web application being deployed behind a reverse-proxy that forwards trailer headers. This issue has been patched in versions 1.0.0-M45 and 0.23.31.

CVSS Details

Base Score
6.3
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
26.8% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available

Weaknesses 1

CWE-444

Affected Products 45

VendorProductVersionRange
typelevelhttp4s* <0.23.31
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any
typelevelhttp4s1.0.0any

References 2

  • github.com https://github.com/http4s/http4s/commit/dd518f7c967e5165813b8d4a48a82b8fab852d41
    Patch
  • github.com https://github.com/http4s/http4s/security/advisories/GHSA-wcwh-7gfw-5wrr
    ExploitVendor Advisory

Remediation

  • github.com https://github.com/http4s/http4s/commit/dd518f7c967e5165813b8d4a48a82b8fab852d41
    Patch