Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-69204

Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)
Back to all
CVE

CVE-2026-69204

Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)

Summary

Ember's HTTP/1.1 request parser does not reject a message that carries both a

Transfer-Encoding and a Content-Length header. RFC 9112 §6.1 requires a

server to treat such a message as a framing error and close the connection.

An intermediary that follows the RFC's CL-strip-and-forward path (or that

prioritises Content-Length) will frame the body differently from Ember,

enabling HTTP request smuggling (CL.TE).

Impact

Server

Request smuggling when ember-server is an origin behind an intermediary that

forwards both headers over a keep-alive backend connection and frames by

Content-Length while Ember frames by chunked:

  • Front-end security bypass: the smuggled request reaches paths the

  intermediary's ACL/auth layer would have blocked, with attacker-chosen

  method and headers.

  • Cross-user request hijack: a dangling smuggled prefix concatenates with the

  next victim's request on the shared backend socket, capturing its headers.

  • Cache poisoning: the smuggled response is associated with the next request

  key in a caching proxy.

Client

ember-client shares the same parser on the response path. An upstream that

sends both headers can desync a pooled client connection. This requires a

malicious or compromised upstream.

Preconditions

  • Unauthenticated remote attacker (server)
  • ember-server as origin behind a keep-alive intermediary
  • Intermediary forwards a request carrying both Transfer-Encoding and

  Content-Length (RFC says it MAY reject; many forward) and frames by

  Content-Length

  • Malicious or compromised upstream (client)

Workarounds

  • Intermediary strictly rejects requests carrying both Transfer-Encoding

  and Content-Length

  • Intermediary buffers and re-encodes request bodies
  • Disable backend keep-alive between the intermediary and Ember

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.2
-
4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
C
H
U
0
-
C
H
U
9.4
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Related Resources

No items found.

References

https://github.com/http4s/http4s/security/advisories/GHSA-8h4c-x2wg-6xp8, https://github.com/http4s/http4s/commit/9feaf8677951a52af906ae9664ff6f0543d9d810, https://github.com/http4s/http4s, https://github.com/http4s/http4s/releases/tag/v0.23.35, https://github.com/http4s/http4s/releases/tag/v1.0.0-M47

Severity

9.4

CVSS Score
0
10

Basic Information

Base CVSS
9.4
EPSS Probability
0.00574%
EPSS Percentile
0.45677%
Introduced Version
0.23.9,0.21.0-M2,0.21.7,0.21.8,0.21.17,0.21.19,0.21.20,0.23.0-M1,1.0.0-M2,1.0.0-M4,1.0.0-M5,1.0.0-M11,1.0.0-M14,1.0.0-M15,1.0.0-M17,1.0.0-M31,1.0.0-M22,0.22.0-M8,0.23.5,1.0.0-M24,0.23.34,0.23.16,1.0.0-M37,0.22.0-M4,0.22.0-M7,1.0.0-M21
Fix Available
0.23.35,1.0.0-M47

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading