CVE-2025-59822
HIGHDescription
Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section. This vulnerability could enable attackers to bypass front-end servers security controls, launch targeted attacks against active users, and poison web caches. A pre-requisite for exploitation involves the web application being deployed behind a reverse-proxy that forwards trailer headers. This issue has been patched in versions 1.0.0-M45 and 0.23.31.
Is your site exposed to CVE-2025-59822?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
| typelevel | http4s |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-59822? +
How severe is CVE-2025-59822? +
What products are affected by CVE-2025-59822? +
How do I check if I'm vulnerable to CVE-2025-59822? +
Related Vulnerabilities
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in ithewei libhv allows HTTP Response Smuggling.This issue affects libhv: through …
HTTP request desynchronization in Ping Identity PingAccess, all versions prior to 8.0.1 affected allows an attacker to send specially crafted …
This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by sending …
An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade …
Connection desynchronization between an HTTP proxy and the model backend. The fixes were rolled out for all proxies in front …
Member Login Script 3.3 contains a client-side desynchronization vulnerability that allows attackers to manipulate HTTP request handling by exploiting Content-Length …