CVE-2026-69215
CVE-2026-69215 is a medium-severity vulnerability with a CVSS 3.x base score of 6.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-565.
Key facts
- Severity: Medium (CVSS 3.x base score 6.8)
- EPSS exploit prediction: 1% (41st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-565
- Published:
- Last modified:
Description
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware uses unanchored substring checks instead of RFC 6265 domain and path matching when deciding whether to attach a stored cookie. A cookie for example.com can consequently be sent to an attacker-controlled hostname such as evilexample.com when an application using the same jar makes an attacker-influenced outbound request. This exposes session or authentication cookies and can enable hijacking of the application’s outbound sessions. This issue is fixed in versions 0.23.35 and 1.0.0-M47.
Frequently asked questions
- What is CVE-2026-69215?
- Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware uses unanchored substring checks instead of RFC 6265 domain and path matching when deciding whether to attach a stored cookie. A cookie for example.com can consequently be sent to an attacker-controlled hostname such as evilexample.com when an application using the same jar makes an attacker-influenced outbound request. This exposes session or authentication cookies and can enable hijacking of the application’s outbound sessions. This issue is fixed in versions 0.23.35 and 1.0.0-M47.
- How severe is CVE-2026-69215?
- CVE-2026-69215 has a CVSS 3.x base score of 6.8, rated medium severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2026-69215 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (41st percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-69215?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-69215 published?
- CVE-2026-69215 was published on 2026-09-15 and last updated on 2026-09-16.
References
- https://github.com/http4s/http4s/commit/c0a37f38d5ee2a568ba57bd9da62f8d79b8b1fcc
- https://github.com/http4s/http4s/releases/tag/v0.23.35
- https://github.com/http4s/http4s/releases/tag/v1.0.0-M47
- https://github.com/http4s/http4s/security/advisories/GHSA-grh8-3p95-f9rr
Other CWE-565 vulnerabilities
- CVE-2023-41084 — Critical (CVSS 10.0): Session management within the web application is incorrect and allows attackers to steal session cookies to perform a…
- CVE-2026-85181 — Critical (CVSS 9.8): CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing…
- CVE-2014-125112 — Critical (CVSS 9.8): Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code…
- CVE-2022-50926 — Critical (CVSS 9.8): WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to…
- CVE-2025-65212 — Critical (CVSS 9.8): An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the…
- CVE-2025-14440 — Critical (CVSS 9.8): The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including,…