THREAT OPS › Threat News › [GHSA] GHSA-crq5-92j2-j7wv (medium) — Http4s: ResourceService and Webjar Service path escape via percent-encoded separators
[GHSA] GHSA-crq5-92j2-j7wv (medium) — Http4s: ResourceService and Webjar Service path escape via percent-encoded separators
GHSA-crq5-92j2-j7wv Severity: medium CVE: CVE-2026-69201
Http4s: ResourceService and Webjar Service path escape via percent-encoded separators
The static content handlers `ResourceService` and `WebjarService` URL decode each path segment and then reject only segments that are exactly `""`, `"."`, or `".."`. A percent-encoded separator (`%2F`) lets an attacker smuggle a `../` segment past that f
Indicators of compromise
- CVE-2026-69201cve
Original source: https://github.com/advisories/GHSA-crq5-92j2-j7wv