THREAT OPS › Threat News › [GHSA] GHSA-wv64-j4fq-5f9x (medium) — Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain
[GHSA] GHSA-wv64-j4fq-5f9x (medium) — Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain
GHSA-wv64-j4fq-5f9x Severity: medium CVE: CVE-2026-69214
Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain
When processing a `Set-Cookie` from a response, the `CookieJar` client middleware trusts the server-supplied `Domain` attribute verbatim, with no check that it domain-matches the host that sent the cookie (RFC6265 §5.3 step 6) and no public suffix check. A malicious or compr
Indicators of compromise
- CVE-2026-69214cve
Original source: https://github.com/advisories/GHSA-wv64-j4fq-5f9x