{"id":"CVE-2026-69216","aliases":["GHSA-jrpm-956j-96jg"],"url":"https://o3.security/vulnerability/CVE-2026-69216","summary":"Http4s: Ember chunk parser lenience (TE.TE request smuggling)","details":"Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s chunk decoder trims the chunk-size token and accepts leading plus or minus signs instead of requiring one or more hexadecimal digits followed by the required CRLF. When an intermediary forwards chunked data without re-encoding and interprets malformed chunk boundaries differently, an unauthenticated attacker can create TE.TE request smuggling that bypasses intermediary controls, poisons caches, or hijacks the request queue. The same response-path leniency can enable response smuggling against an ember-client used as a gateway when the upstream is malicious or compromised. This issue is fixed in versions 0.23.35 and 1.0.0-M47.","published":"2026-09-15T18:59:50.609Z","modified":"2026-09-16T03:47:17.582955243Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Maven","name":"org.http4s:http4s-ember-core_2.12","fixedVersion":"0.23.35"},{"ecosystem":"Maven","name":"org.http4s:http4s-ember-core_2.13","fixedVersion":"0.23.35"},{"ecosystem":"Maven","name":"org.http4s:http4s-ember-core_3","fixedVersion":"0.23.35"},{"ecosystem":"Maven","name":"org.http4s:http4s-ember-core_2.13","fixedVersion":"1.0.0-M47"},{"ecosystem":"Maven","name":"org.http4s:http4s-ember-core_3","fixedVersion":"1.0.0-M47"}],"fix":{"url":"https://github.com/http4s/http4s/commit/d78612a5abd5a2547487598d3342be05573e16f0","label":"http4s/http4s@d78612a"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/69xxx/CVE-2026-69216.json"},{"type":"FIX","url":"https://github.com/http4s/http4s/commit/d78612a5abd5a2547487598d3342be05573e16f0"},{"type":"WEB","url":"https://github.com/http4s/http4s/releases/tag/v0.23.35"},{"type":"WEB","url":"https://github.com/http4s/http4s/releases/tag/v1.0.0-M47"},{"type":"ADVISORY","url":"https://github.com/http4s/http4s/security/advisories/GHSA-jrpm-956j-96jg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69216"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-16T03:47:17.582955243Z"}}