THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-crq5-92j2-j7wv (medium) — Http4s: ResourceService and Webjar Service path escape via percent-encoded separators

[GHSA] GHSA-crq5-92j2-j7wv (medium) — Http4s: ResourceService and Webjar Service path escape via percent-encoded separators

medgithub_advisoriesPublished 2026-09-15

GHSA-crq5-92j2-j7wv Severity: medium CVE: CVE-2026-69201

Http4s: ResourceService and Webjar Service path escape via percent-encoded separators

The static content handlers `ResourceService` and `WebjarService` URL decode each path segment and then reject only segments that are exactly `""`, `"."`, or `".."`. A percent-encoded separator (`%2F`) lets an attacker smuggle a `../` segment past that f

Indicators of compromise

Original source: https://github.com/advisories/GHSA-crq5-92j2-j7wv