Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Http4s HIGH 7.5
CVE-2025-59822

Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s is vulnerable to HTTP Request…

Fix: 0.23.31+
Fix from $1,950 2025-09-23
Grackle HIGH 7.5
CVE-2023-50730

Grackle is a GraphQL server written in functional Scala, built on the Typelevel stack. The GraphQL specification requires that GraphQL fragments must…

Fix: 0.18.0+
Fix from $1,950 2023-12-22
Http4s MEDIUM 5.3
CVE-2023-22465

Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the `User-…

Fix: 0.21.34 / 0.22.15+
Fix from $1,600 2023-01-04
Fs2 CRITICAL 9.8
CVE-2022-31183

fs2 is a compositional, streaming I/O library for Scala. When establishing a server-mode `TLSSocket` using `fs2-io` on Node.js, the parameter `reques…

Fix: 3.2.11+
Fix from $2,300 2022-08-01
Jawn HIGH 7.5
CVE-2022-21653

Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don't override `obj…

Fix: 1.3.2+
Fix from $1,950 2022-01-05
Http4s CRITICAL 9.1
CVE-2021-39185

Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0.22.2, 0.23.0, 0.23.1, and 1.…

Fix: after 0.22.2
Fix from $2,300 2021-09-01
Http4s MEDIUM 5.8
CVE-2021-32643

Http4s is a Scala interface for HTTP services. `StaticFile.fromUrl` can leak the presence of a directory on a server when the `URL` scheme is not `fi…

Fix: 0.21.24+
Fix from $1,600 2021-05-27
Blaze HIGH 7.5
CVE-2021-21293

blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. All servers running blaze-core before version 0.14.15 are a…

Fix: 0.14.15+
Fix from $1,950 2021-02-02
Http4s HIGH 7.5
CVE-2021-21294

Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Http4s before versions 0.21.17, 0.22.0-M2, and 1.0.0-M14 have…

Fix: 0.21.17+
Fix from $1,950 2021-02-02
Http4s HIGH 7.5
CVE-2020-5280EPSS 7%

http4s before versions 0.18.26, 0.20.20, and 0.21.2 has a local file inclusion vulnerability. This vulnerability applies to all users of org.http4s.s…

Fix: 0.18.26 / 0.20.20+
Fix from $1,950 2020-03-25