11 Total advisories
11 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.http4s:http4s-ember-core_2.12 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-88975
Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZE
HIGH 7.5
CVE-2026-69213
Http4s Ember HTTP/2 has an unbounded outbound frame queue
MEDIUM 5.4
CVE-2026-69216
Http4s: Ember chunk parser lenience (TE.TE request smuggling)
HIGH 7.5
CVE-2026-69218
Http4s Ember HTTP/2: unbounded continuation frame accumulation
HIGH 7.5
CVE-2026-69203
Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS
HIGH 8.7
CVE-2026-69205
Http4s Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling)
UNKNOWN
CVE-2026-69204
Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)
HIGH 7.5
CVE-2026-69202
Http4s Ember HTTP/2: unbounded inbound body buffering
MEDIUM 5.9
CVE-2026-69206
Http4s: DigestAuth allows replay of captured requests
UNKNOWN
CVE-2026-54556
http4s has HTTP/2 Denial of Service with Ember Backend
UNKNOWN
CVE-2025-59822
Http4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes