maven package report

Is org.http4s:http4s-core safe?

1 known vulnerability, worst severity MODERATE.

cvss
5.8

how bad it is if exploited, out of 10

epss
1.4%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-6h7w-fc84-x7p6, the advisory selected below

// advisories

GHSA-6h7w-fc84-x7p6

MODERATECVE-2021-32643

StaticFile.fromUrl can leak the presence of a directory on a server when the URL scheme is not file://, and the URL points to a fetchable resource under its scheme and authority. The function returns F[None], indicating no resource, if url.getFile is a directory, without first checking the scheme or authority of the URL. If a URL connection to the scheme and URL would return a stream, and the pa

Affected
>= 0.22.0-M1, <= 0.22.0-M8, >= 0.21.7, < 0.21.24, >= 1.0.0-M1, <= 1.0.0-M22, = 0.23.0-M1
Fixed in
0.22.0-RC1
Weakness
CWE-22
Published
2021-05-28
Source
github

GHSANVDMITREreferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 02:57 UTC. The most recent advisory here was published 2021-05-28. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is org.http4s:http4s-core safe? maven package security report | CyberXYZ