CVE-2026-69214: Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain
When processing a Set-Cookie from a response, the CookieJar client middleware trusts the server-supplied Domain attribute verbatim, with no check that it domain-matches the host that sent the cookie (RFC6265 §5.3 step 6) and no public suffix check. A malicious or compromised server can therefore plant a cookie for any domain in the cookie jar, which is subsequently set on the client’s next request to that victim domain, enabling session fixation or overwriting security-relevant cookies.
References
- github.com/advisories/GHSA-wv64-j4fq-5f9x
- github.com/http4s/http4s/commit/87535f7288f3baaf6736e2735087e473762b5b2f
- github.com/http4s/http4s/releases/tag/v0.23.35
- github.com/http4s/http4s/releases/tag/v1.0.0-M47
- github.com/http4s/http4s/security/advisories/GHSA-wv64-j4fq-5f9x
- nvd.nist.gov/vuln/detail/CVE-2026-69214
Code Behaviors & Features
Detect and mitigate CVE-2026-69214 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →