Known Vulnerabilities for products from Typelevel
Listed below are 9 of the newest known vulnerabilities associated with the vendor "Typelevel".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-22465 json | Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, a... | 5.3 - MEDIUM | 2023-01-04 | 2023-11-07 |
| CVE-2022-31183 json | fs2 is a compositional, streaming I/O library for Scala. When establishing a server-mode `TLSSocket` using `fs2-io` on Node.j... | 9.8 - CRITICAL | 2022-08-01 | 2022-08-09 |
| CVE-2022-21653 json | Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade`... | 7.5 - HIGH | 2022-01-05 | 2022-01-12 |
| CVE-2021-41084 json | http4s is an open source scala interface for HTTP. In affected versions http4s is vulnerable to response-splitting or request... | 4.7 - MEDIUM | 2021-09-21 | 2022-10-25 |
| CVE-2021-39185 json | Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0.22.2... | 9.1 - CRITICAL | 2021-09-01 | 2021-09-15 |
| CVE-2021-32643 json | Http4s is a Scala interface for HTTP services. `StaticFile.fromUrl` can leak the presence of a directory on a server when the... | 5.8 - MEDIUM | 2021-05-27 | 2021-06-10 |
| CVE-2021-21294 json | Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Http4s before versions 0.21.17, 0.22.... | 7.5 - HIGH | 2021-02-02 | 2022-10-24 |
| CVE-2021-21293 json | blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. All servers running blaze-core befo... | 7.5 - HIGH | 2021-02-02 | 2022-10-25 |
| CVE-2020-5280 json | http4s before versions 0.18.26, 0.20.20, and 0.21.2 has a local file inclusion vulnerability. This vulnerability applies to a... | 7.5 - HIGH | 2020-03-25 | 2020-03-30 |