THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jrpm-956j-96jg (medium) — Http4s: Ember chunk parser lenience (TE.TE request smuggling)

[GHSA] GHSA-jrpm-956j-96jg (medium) — Http4s: Ember chunk parser lenience (TE.TE request smuggling)

medgithub_advisoriesPublished 2026-09-15

GHSA-jrpm-956j-96jg Severity: medium CVE: CVE-2026-69216

Http4s: Ember chunk parser lenience (TE.TE request smuggling)

## Summary

Ember's chunk decoder parses the size token leniently: it strips leading and trailing whitespace and accepts a leading `+` or `-` sign. RFC9112 §7.1 defines `chunk-size = 1*HEXDIG`. An intermediary that parses the chunk boundary differently (or rejects it) will dis

Indicators of compromise

Original source: https://github.com/advisories/GHSA-jrpm-956j-96jg