THREAT OPS › Threat News › [GHSA] GHSA-8h4c-x2wg-6xp8 (critical) — Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)
[GHSA] GHSA-8h4c-x2wg-6xp8 (critical) — Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)
GHSA-8h4c-x2wg-6xp8 Severity: critical CVE: CVE-2026-69204
Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)
## Summary
Ember's HTTP/1.1 request parser does not reject a message that carries both a `Transfer-Encoding` and a `Content-Length` header. RFC 9112 §6.1 requires a server to treat such a message as a framing error and close the connection. An
Indicators of compromise
- CVE-2026-69204cve
Original source: https://github.com/advisories/GHSA-8h4c-x2wg-6xp8