THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-wv64-j4fq-5f9x (medium) — Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain

[GHSA] GHSA-wv64-j4fq-5f9x (medium) — Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain

medgithub_advisoriesPublished 2026-09-15

GHSA-wv64-j4fq-5f9x Severity: medium CVE: CVE-2026-69214

Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain

When processing a `Set-Cookie` from a response, the `CookieJar` client middleware trusts the server-supplied `Domain` attribute verbatim, with no check that it domain-matches the host that sent the cookie (RFC6265 §5.3 step 6) and no public suffix check. A malicious or compr

Indicators of compromise

Original source: https://github.com/advisories/GHSA-wv64-j4fq-5f9x