CVE-2021-41084
unknown
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
โ
Description
Response Splitting from unsanitized headers
Predictions
Exploit likelihood
30%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Package impact
References
- https://github.com/http4s/http4s/security/advisories/GHSA-5vcm-3xc3-w7x3
- https://nvd.nist.gov/vuln/detail/CVE-2021-41084
- https://github.com/http4s/http4s/commit/d02007db1da4f8f3df2dbf11f1db9ac7afc3f9d8
- https://github.com/http4s/http4s
- https://httpwg.org/http-core/draft-ietf-httpbis-semantics-latest.html#fields.values
- https://owasp.org/www-community/attacks/HTTP_Response_Splitting
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.