GHSA-crq5-92j2-j7wv

Suggest an improvement
Source
https://github.com/advisories/GHSA-crq5-92j2-j7wv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-crq5-92j2-j7wv/GHSA-crq5-92j2-j7wv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-crq5-92j2-j7wv
Aliases
Published
2026-09-15T20:01:12Z
Modified
2026-09-15T20:15:05Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Http4s: ResourceService and Webjar Service path escape via percent-encoded separators
Details

The static content handlers ResourceService and WebjarService URL decode each path segment and then reject only segments that are exactly "", ".", or "..". A percent-encoded separator (%2F) lets an attacker smuggle a ../ segment past that filter and escape the configured base, reading resources that should not be public.

On Windows, a similar attack exists with (%5C).

Impact

Disclosure of classpath or webjar resources outside the configured base.

Preconditions

  • Application uses ResourceService (with a non-root base path) or WebjarService
  • At least one classpath entry is served from a directory (e.g. sbt run, exploded .war)
  • Backend forwards %2F/%5C without normalizing (e.g., Ember, Blaze)

Fixes

The patch rejects any decoded path segment containing / (%2F) or \ (%5C) with a 400 Bad Request in ResourceService and WebjarService.

FileService was not exploitable, but the same guards are applied for consistency and to remove its reliance on path normalization.

Workarounds

  • Deploy as a fat jar, with no filesystem directories on the classpath.
  • Front the service with a proxy that rejects/normalizes %2F and %5C in the request path.
Database specific
{
    "cwe_ids":  [
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-15T20:01:12Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

Maven
org.http4s:http4s-server_2.12

Package

Name
org.http4s:http4s-server_2.12
View open source insights on deps.dev
Purl
pkg:maven/org.http4s/http4s-server_2.12

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.23.35

Affected versions

0.*
0.10.0-M10
0.15.0
0.15.0a
0.15.1
0.15.1a
0.15.2
0.15.2a
0.15.3
0.15.3a
0.15.4
0.15.4a
0.15.5
0.15.5a
0.15.6
0.15.6a
0.15.7
0.15.7a
0.15.8
0.15.8a
0.15.9
0.15.9a
0.15.10
0.15.10a
0.15.11
0.15.11a
0.15.12
0.15.12a
0.15.13
0.15.13a
0.15.14
0.15.14a
0.15.15
0.15.15a
0.15.16
0.15.16a
0.16.0-M1
0.16.0-M2
0.16.0-M3
0.16.0-RC1
0.16.0-RC2
0.16.0-RC3
0.16.0
0.16.0a-M1
0.16.0a-M2
0.16.0a-M3
0.16.0a-RC1
0.16.0a-RC2
0.16.0a-RC3
0.16.0a
0.16.1
0.16.1a
0.16.2
0.16.2a
0.16.3
0.16.3a
0.16.4
0.16.4a
0.16.5
0.16.5a
0.16.6
0.16.6a
0.17.0-M1
0.17.0-M2
0.17.0-M3
0.17.0-RC1
0.17.0-RC2
0.17.0-RC3
0.17.0
0.17.1
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.18.0-M1
0.18.0-M2
0.18.0-M3
0.18.0-M4
0.18.0-M5
0.18.0-M6
0.18.0-M7
0.18.0-M8
0.18.0-M9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.18.5
0.18.6
0.18.7
0.18.8
0.18.9
0.18.10
0.18.11
0.18.12
0.18.13
0.18.14
0.18.15
0.18.16
0.18.17
0.18.18
0.18.19
0.18.20
0.18.21
0.18.22
0.18.23
0.18.24
0.18.25
0.18.26
0.19.0-M1
0.19.0-M2
0.19.0-M3
0.19.0-M4
0.19.0
0.20.0-M1
0.20.0-M2
0.20.0-M3
0.20.0-M4
0.20.0-M5
0.20.0-M6
0.20.0-M7
0.20.0-RC1
0.20.0
0.20.1
0.20.2
0.20.3
0.20.4
0.20.5
0.20.6
0.20.7
0.20.8
0.20.9
0.20.10
0.20.11
0.20.12
0.20.13
0.20.14
0.20.15
0.20.16
0.20.17
0.20.18
0.20.19
0.20.20
0.20.21
0.20.22
0.20.23
0.21.0-M1
0.21.0-M2
0.21.0-M3
0.21.0-M4
0.21.0-M5
0.21.0-M6
0.21.0-RC1
0.21.0-RC2
0.21.0-RC3
0.21.0-RC4
0.21.0-RC5
0.21.0
0.21.1
0.21.2
0.21.3
0.21.4
0.21.5
0.21.6
0.21.7
0.21.8
0.21.9
0.21.11
0.21.12
0.21.13
0.21.14
0.21.15
0.21.16
0.21.17
0.21.18
0.21.19
0.21.20
0.21.21
0.21.22
0.21.23
0.21.24
0.21.25
0.21.26
0.21.27
0.21.28
0.21.29
0.21.30
0.21.31
0.21.32
0.21.33
0.21.34
0.22.0-M1
0.22.0-M2
0.22.0-M3
0.22.0-M4
0.22.0-M5
0.22.0-M6
0.22.0-M7
0.22.0-M8
0.22.0-RC1
0.22.0
0.22-53-01128f5
0.22-96-55d3184
0.22-129-24d065b
0.22-143-49b5a8d
0.22.1
0.22.2
0.22.3
0.22.4
0.22.5
0.22.6
0.22.7
0.22.8
0.22.9
0.22.10
0.22.11
0.22.12
0.22.13
0.22.14
0.22.15
0.23.0-M1
0.23.0-RC1
0.23.0
0.23.1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19-RC1
0.23.19-RC2
0.23.19-RC3
0.23.19
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.25
0.23.26
0.23.27
0.23.28
0.23.29
0.23.30
0.23.31
0.23.32
0.23.33
0.23.34

Database specific

last_known_affected_version_range
"<= 0.23.34"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-crq5-92j2-j7wv/GHSA-crq5-92j2-j7wv.json"
org.http4s:http4s-server_2.13

Package

Name
org.http4s:http4s-server_2.13
View open source insights on deps.dev
Purl
pkg:maven/org.http4s/http4s-server_2.13

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.23.35

Affected versions

0.*
0.10.0-M10
0.21.0-M1
0.21.0-M2
0.21.0-M3
0.21.0-M4
0.21.0-M5
0.21.0-M6
0.21.0-RC1
0.21.0-RC2
0.21.0-RC3
0.21.0-RC4
0.21.0-RC5
0.21.0
0.21.1
0.21.2
0.21.3
0.21.4
0.21.5
0.21.6
0.21.7
0.21.8
0.21.9
0.21.11
0.21.12
0.21.13
0.21.14
0.21.15
0.21.16
0.21.17
0.21.18
0.21.19
0.21.20
0.21.21
0.21.22
0.21.23
0.21.24
0.21.25
0.21.26
0.21.27
0.21.28
0.21.29
0.21.30
0.21.31
0.21.32
0.21.33
0.21.34
0.22.0-M1
0.22.0-M2
0.22.0-M3
0.22.0-M4
0.22.0-M5
0.22.0-M6
0.22.0-M7
0.22.0-M8
0.22.0-RC1
0.22.0
0.22-53-01128f5
0.22-96-55d3184
0.22-129-24d065b
0.22-143-49b5a8d
0.22.1
0.22.2
0.22.3
0.22.4
0.22.5
0.22.6
0.22.7
0.22.8
0.22.9
0.22.10
0.22.11
0.22.12
0.22.13
0.22.14
0.22.15
0.23.0-M1
0.23.0-RC1
0.23.0
0.23.1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19-RC1
0.23.19-RC2
0.23.19-RC3
0.23.19
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.25
0.23.26
0.23.27
0.23.28
0.23.29
0.23.30
0.23.31
0.23.32
0.23.33
0.23.34

Database specific

last_known_affected_version_range
"<= 0.23.34"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-crq5-92j2-j7wv/GHSA-crq5-92j2-j7wv.json"
org.http4s:http4s-server_3

Package

Name
org.http4s:http4s-server_3
View open source insights on deps.dev
Purl
pkg:maven/org.http4s/http4s-server_3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.23.35

Affected versions

0.*
0.22.0-M8
0.22.0-RC1
0.22.0
0.22.1
0.22.2
0.22.3
0.22.4
0.22.5
0.22.6
0.22.7
0.22.8
0.22.9
0.22.10
0.22.11
0.22.12
0.22.13
0.22.14
0.22.15
0.23.0-M1
0.23.0-RC1
0.23.0
0.23.1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19-RC1
0.23.19-RC2
0.23.19-RC3
0.23.19
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.25
0.23.26
0.23.27
0.23.28
0.23.29
0.23.30
0.23.31
0.23.32
0.23.33
0.23.34

Database specific

last_known_affected_version_range
"<= 0.23.34"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-crq5-92j2-j7wv/GHSA-crq5-92j2-j7wv.json"
org.http4s:http4s-server_3

Package

Name
org.http4s:http4s-server_3
View open source insights on deps.dev
Purl
pkg:maven/org.http4s/http4s-server_3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0-M1
Fixed
1.0.0-M47

Affected versions

1.*
1.0.0-M22
1.0.0-M23
1.0.0-M24
1.0.0-M25
1.0.0-M27
1.0.0-M28
1.0.0-M29
1.0.0-M30
1.0.0-M31
1.0.0-M32
1.0.0-M33
1.0.0-M34
1.0.0-M35
1.0.0-M36
1.0.0-M37
1.0.0-M38
1.0.0-M39
1.0.0-M40
1.0.0-M41
1.0.0-M42
1.0.0-M43
1.0.0-M44
1.0.0-M45
1.0.0-M46

Database specific

last_known_affected_version_range
"<= 1.0.0-M46"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-crq5-92j2-j7wv/GHSA-crq5-92j2-j7wv.json"
org.http4s:http4s-server_2.13

Package

Name
org.http4s:http4s-server_2.13
View open source insights on deps.dev
Purl
pkg:maven/org.http4s/http4s-server_2.13

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0-M1
Fixed
1.0.0-M47

Affected versions

1.*
1.0.0-M2
1.0.0-M3
1.0.0-M4
1.0.0-M5
1.0.0-M6
1.0.0-M7
1.0.0-M8
1.0.0-M9
1.0.0-M10
1.0.0-M13
1.0.0-M14
1.0.0-M15
1.0.0-M16
1.0.0-M17
1.0.0-M18
1.0.0-M19
1.0.0-M20
1.0.0-M21
1.0.0-M22
1.0.0-M23
1.0.0-M24
1.0.0-M25
1.0.0-M27
1.0.0-M28
1.0.0-M29
1.0.0-M30
1.0.0-M31
1.0.0-M32
1.0.0-M33
1.0.0-M34
1.0.0-M35
1.0.0-M36
1.0.0-M37
1.0.0-M38
1.0.0-M39
1.0.0-M40
1.0.0-M41
1.0.0-M42
1.0.0-M43
1.0.0-M44
1.0.0-M45
1.0.0-M46

Database specific

last_known_affected_version_range
"<= 1.0.0-M46"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-crq5-92j2-j7wv/GHSA-crq5-92j2-j7wv.json"