THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8h4c-x2wg-6xp8 (critical) — Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)

[GHSA] GHSA-8h4c-x2wg-6xp8 (critical) — Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)

medgithub_advisoriesPublished 2026-09-15

GHSA-8h4c-x2wg-6xp8 Severity: critical CVE: CVE-2026-69204

Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)

## Summary

Ember's HTTP/1.1 request parser does not reject a message that carries both a `Transfer-Encoding` and a `Content-Length` header. RFC 9112 §6.1 requires a server to treat such a message as a framing error and close the connection. An

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8h4c-x2wg-6xp8