CVE-2023-22465 Information

Description

Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34 0.22.15 0.23.17 and 1.0.0-M38 the User-Agent and Server header parsers are susceptible to a fatal error on certain inputs. In http4s modeled headers are lazily parsed so this only applies to services that explicitly request these typed headers. Fixes are released in 0.21.34 0.22.15 0.23.17 and 1.0.0-M38. As a workaround use the weakly typed header interface.

Reference

https://github.com/http4s/http4s/security/advisories/GHSA-54w6-vxfh-fw7f

Share on: