CVE-2023-22465 Information
Jan 05, 2023
cve
Description
Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34 0.22.15 0.23.17 and 1.0.0-M38 the User-Agent and Server header parsers are susceptible to a fatal error on certain inputs. In http4s modeled headers are lazily parsed so this only applies to services that explicitly request these typed headers. Fixes are released in 0.21.34 0.22.15 0.23.17 and 1.0.0-M38. As a workaround use the weakly typed header interface.
Reference
https://github.com/http4s/http4s/security/advisories/GHSA-54w6-vxfh-fw7f
Share on: