Http4s
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 4 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from August 12, 2026 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
No CWE data available
Most Affected Products
Recent Vulnerabilities
See more →Http4s: WebSocket decoder accepts negative length, causing infinite decode loop
Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin
Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain
http4s-blaze-server: Unbounded WebSocket message aggregation
Monitor Http4s in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.