← Vulnerability feed

Vulnerability record · CVE-2020-5280 · published 25 March 2020

CVE-2020-5280: Typelevel http4s relative path traversal vulnerability

Typelevel · Http4s

http4s before versions 0.18.26, 0.20.20, and 0.21.2 has a local file inclusion vulnerability. This vulnerability applies to all users of org.http4s.server.staticcontent.FileService, org.http4s.server.staticcontent.ResourceService and org.http4s.server.staticcontent.WebjarService. URI normalization is applied incorrectly. Requests whose path info contain ../ or // can expose resources outside of the configured location. This issue is patched in versions 0.18.26, 0.20.20, and 0.21.2. Note that 0.19.0 is a deprecated release and has never been supported.

7.5 CVSS 3.1 High EPSS 7.0% · top 6.1% CWE-23 · Relative path traversalCWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 5.0
7.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

http4s before versions 0.18.26, 0.20.20, and 0.21.2 has a local file inclusion vulnerability. This vulnerability applies to all users of org.http4s.server.staticcontent.FileService, org.http4s.server.staticcontent.ResourceService and org.http4s.server.staticcontent.WebjarService. URI normalization is applied incorrectly. Requests whose path info contain ../ or // can expose resources outside of the configured location. This issue is patched in versions 0.18.26, 0.20.20, and 0.21.2. Note that 0.19.0 is a deprecated release and has never been supported.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-5280 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2021-39185Typelevel http4s origin validation error vulnerabilityHttp4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0.22.2, 0.23.0, 0.23.1, and 1.…EPSS 0.59%7.5CVE-2021-21294Typelevel http4s uncontrolled resource consumption vulnerabilityHttp4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Http4s before versions 0.21.17, 0.22.0-M2, and 1.0.0-M14 have…EPSS 2.1%6.3CVE-2025-59822Typelevel http4s http request smuggling vulnerabilityHttp4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s is vulnerable to HTTP Request…EPSS 0.37%5.8CVE-2021-32643Typelevel http4s path traversal vulnerabilityHttp4s is a Scala interface for HTTP services. `StaticFile.fromUrl` can leak the presence of a directory on a server when the `URL` scheme is not `fi…EPSS 1.4%5.3CVE-2023-22465Typelevel http4s improper input validation vulnerabilityHttp4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the `User-…EPSS 0.85%4.7CVE-2021-41084Typelevel http4s server-side request forgery (ssrf) vulnerabilityhttp4s is an open source scala interface for HTTP. In affected versions http4s is vulnerable to response-splitting or request-splitting attacks when …EPSS 1.2%6.7CVE-2026-34926Trend Micro Apex One on-premise server directory traversal enables agent code injectionA relative path traversal (CWE-23) in the Apex One on-premise server lets an attacker who already holds administrative credentials on the server modi…KEVEPSS 0.54%analysed7.3CVE-2024-27199JetBrains TeamCity path traversal enables limited admin actionsJetBrains TeamCity before 2023.11.4 is vulnerable to relative path traversal that lets an unauthenticated remote party perform limited administrative…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2020-5280), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.