typelevel records
11 published records for vendor typelevel.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-400 Uncontrolled Resource Consumption4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-23 Relative Path Traversal1
- CWE-295 Improper Certificate Validation1
- CWE-346 Origin Validation Error1
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-31183No exploit | mTLS client verification is skipped in fs2 on Node.jstypelevel · fs2 · CWE-295 | Critical9.8 | — | 0.8% | Aug 1, 2022 |
36Monitor | CVE-2021-39185No exploit | Default CORS config allows any origin with credentialstypelevel · http4s · CWE-346 | Critical9.1 | — | 0.6% | Sep 1, 2021 |
32Monitor | CVE-2020-5280No exploit | Local file inclusion vulnerability in http4stypelevel · http4s · CWE-23 | High7.5 | — | 7.0% | Mar 25, 2020 |
31Monitor | CVE-2021-21294No exploit | Unbounded connection acceptance in http4s-blaze-servertypelevel · http4s · CWE-400 | High7.5 | — | 2.1% | Feb 2, 2021 |
31Monitor | CVE-2021-21293No exploit | Unbounded connection acceptance leads to file handle exhaustiontypelevel · blaze · CWE-400 | High7.5 | — | 2.1% | Feb 2, 2021 |
30Monitor | CVE-2023-50730No exploit | Grackle has StackOverflowError in GraphQL query processingtypelevel · grackle · CWE-400 | High7.5 | — | 0.8% | Dec 22, 2023 |
30Monitor | CVE-2022-21653No exploit | Hash collision in typelevel jawntypelevel · jawn · CWE-400 | High7.5 | — | 0.8% | Jan 5, 2022 |
25Monitor | CVE-2025-59822No exploit | Http4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sectiontypelevel · http4s · CWE-444 | Medium6.3 | — | 0.4% | Sep 23, 2025 |
23Monitor | CVE-2021-32643No exploit | StaticFile.fromUrl can leak presence of a directorytypelevel · http4s · CWE-22 | Medium5.8 | — | 1.4% | May 27, 2021 |
21Monitor | CVE-2023-22465No exploit | Http4s has fatal error parsing User-Agent and Server headerstypelevel · http4s · CWE-20 | Medium5.3 | — | 0.8% | Jan 4, 2023 |
18Monitor | CVE-2021-41084No exploit | Response Splitting from unsanitized headers in http4stypelevel · http4s · CWE-918 | Medium4.7 | — | 1.2% | Sep 21, 2021 |
- CVE-2022-3118339Monitor
mTLS client verification is skipped in fs2 on Node.js
CriticalCVSS 9.8No exploitEPSS 1%typelevel · fs2Aug 1, 2022
- CVE-2021-3918536Monitor
Default CORS config allows any origin with credentials
CriticalCVSS 9.1No exploitEPSS 1%typelevel · http4sSep 1, 2021
- CVE-2020-528032Monitor
Local file inclusion vulnerability in http4s
HighCVSS 7.5No exploitEPSS 7%typelevel · http4sMar 25, 2020
- CVE-2021-2129431Monitor
Unbounded connection acceptance in http4s-blaze-server
HighCVSS 7.5No exploitEPSS 2%typelevel · http4sFeb 2, 2021
- CVE-2021-2129331Monitor
Unbounded connection acceptance leads to file handle exhaustion
HighCVSS 7.5No exploitEPSS 2%typelevel · blazeFeb 2, 2021
- CVE-2023-5073030Monitor
Grackle has StackOverflowError in GraphQL query processing
HighCVSS 7.5No exploitEPSS 1%typelevel · grackleDec 22, 2023
- CVE-2022-2165330Monitor
Hash collision in typelevel jawn
HighCVSS 7.5No exploitEPSS 1%typelevel · jawnJan 5, 2022
- CVE-2025-5982225Monitor
Http4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section
MediumCVSS 6.3No exploitEPSS 0%typelevel · http4sSep 23, 2025
- CVE-2021-3264323Monitor
StaticFile.fromUrl can leak presence of a directory
MediumCVSS 5.8No exploitEPSS 1%typelevel · http4sMay 27, 2021
- CVE-2023-2246521Monitor
Http4s has fatal error parsing User-Agent and Server headers
MediumCVSS 5.3No exploitEPSS 1%typelevel · http4sJan 4, 2023
- CVE-2021-4108418Monitor
Response Splitting from unsanitized headers in http4s
MediumCVSS 4.7No exploitEPSS 1%typelevel · http4sSep 21, 2021