CVE-2025-59822

Description

Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section. This vulnerability could enable attackers to bypass front-end servers security controls, launch targeted attacks against active users, and poison web caches. A pre-requisite for exploitation involves the web application being deployed behind a reverse-proxy that forwards trailer headers. This issue has been patched in versions 1.0.0-M45 and 0.23.31.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.065

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2025-59822 are fixed in Http4s - http4s-ember-core_2.12 0.23.31Windows
Vulnerabilities CVE-2025-59822 are fixed in Http4s - http4s-ember-core_2.13 0.23.31Windows
Vulnerabilities CVE-2025-59822 are fixed in Http4s - http4s-ember-core_2.13 1.0.0Windows
Vulnerabilities CVE-2025-59822 are fixed in Http4s - http4s-ember-core_3 0.23.31Windows
Vulnerabilities CVE-2025-59822 are fixed in Http4s - http4s-ember-core_3 1.0.0Windows
Vulnerabilities CVE-2025-59822 are fixed in Http4s - http4s-ember-core_2.12 for Linux 0.23.31Linux
Vulnerabilities CVE-2025-59822 are fixed in Http4s - http4s-ember-core_2.13 for Linux 0.23.31Linux
Vulnerabilities CVE-2025-59822 are fixed in Http4s - http4s-ember-core_2.13 for Linux 1.0.0Linux
Vulnerabilities CVE-2025-59822 are fixed in Http4s - http4s-ember-core_3 for Linux 0.23.31Linux
Vulnerabilities CVE-2025-59822 are fixed in Http4s - http4s-ember-core_3 for Linux 1.0.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234