Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin
GHSA-grh8-3p95-f9rr · CVE-2026-69215
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
The CookieJar client middleware decides whether to attach a cookie to an outgoing request using an unanchored substring test on the host and path, instead of the domain match specified by RFC6265 5.1.3. A cookie stored for example.com is therefore sent to any host whose name merely contains example.com (e.g. evilexample.com), leaking potentially sensitive cookies to an attacker-chosen host.
Impact
Disclosure of session and authentication cookies to an attacker-controlled host, enabling session hijack of the application's outbound calls.
Preconditions
- Application uses the
CookieJarclient middleware. - Application can be induced to make an outbound request to a host controlled by the attacker, where the hostname contains the targeted domain as a substring.
Workarounds
- Do not use the
CookieJarwith clients that fetch attacker-influenced URLs - Apply a separate
CookieJarper trusted origin.
References
- WEB https://github.com/http4s/http4s/security/advisories/GHSA-grh8-3p95-f9rr
- WEB https://github.com/http4s/http4s/commit/c0a37f38d5ee2a568ba57bd9da62f8d79b8b1fcc
- PACKAGE https://github.com/http4s/http4s
- WEB https://github.com/http4s/http4s/releases/tag/v0.23.35
- WEB https://github.com/http4s/http4s/releases/tag/v1.0.0-M47
Ready to move
Start Securing
Free, no credit card | First findings in minutes