{"id":"CVE-2021-41084","details":"http4s is an open source scala interface for HTTP. In affected versions http4s is vulnerable to response-splitting or request-splitting attacks when untrusted user input is used to create any of the following fields: Header names (`Header.name`å), Header values (`Header.value`), Status reason phrases (`Status.reason`), URI paths (`Uri.Path`), URI authority registered names (`URI.RegName`) (through 0.21). This issue has been resolved in versions 0.21.30, 0.22.5, 0.23.4, and 1.0.0-M27 perform the following. As a matter of practice http4s services and client applications should sanitize any user input in the aforementioned fields before returning a request or response to the backend. The carriage return, newline, and null characters are the most threatening.","aliases":["GHSA-5vcm-3xc3-w7x3"],"modified":"2026-02-24T11:41:03.787384Z","published":"2021-09-21T18:15:07.427Z","related":["GHSA-5vcm-3xc3-w7x3"],"references":[{"type":"ADVISORY","url":"https://github.com/http4s/http4s/commit/d02007db1da4f8f3df2dbf11f1db9ac7afc3f9d8"},{"type":"ADVISORY","url":"https://github.com/http4s/http4s/security/advisories/GHSA-5vcm-3xc3-w7x3"},{"type":"ADVISORY","url":"https://httpwg.org/http-core/draft-ietf-httpbis-semantics-latest.html#fields.values"},{"type":"ADVISORY","url":"https://owasp.org/www-community/attacks/HTTP_Response_Splitting"},{"type":"FIX","url":"https://github.com/http4s/http4s/commit/d02007db1da4f8f3df2dbf11f1db9ac7afc3f9d8"},{"type":"EVIDENCE","url":"https://github.com/http4s/http4s/security/advisories/GHSA-5vcm-3xc3-w7x3"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/http4s/http4s","events":[{"introduced":"0"},{"fixed":"d02007db1da4f8f3df2dbf11f1db9ac7afc3f9d8"},{"introduced":"06db471f053023ce3ffd7c568ce46d33551d1d69"},{"fixed":"1bdc15f793865c92008b6a4d76d1ce818be27ac9"},{"introduced":"3e98ea4a63e741c7f9d5e917d48d2ee8fab54476"},{"fixed":"4695eb16773b4ee9ed37b2f0d51d4ded16772779"}]}],"versions":["v0.21.26","v0.21.27","v0.21.28","v0.21.29","v0.22.0","v0.22.1","v0.22.2","v0.22.3","v0.22.4","v0.22.5","v0.23.0","v0.23.1","v0.23.2","v0.23.3","v1.0.0-M24","v1.0.0-M25","v1.0.0-M26"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-41084.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N"}]}