Typelevel maintains a focused ecosystem of Scala libraries and frameworks for functional programming, including widely embedded HTTP and streaming components such as http4s, fs2, and Blaze that serve high-traffic services and integrations across the JVM landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through resource-exhaustion and validation weaknesses including uncontrolled resource consumption, path traversal, certificate validation, and input handling that reflect the parser-oriented and network-facing nature of these foundational libraries. Defenders should prioritize tracking this vendor's releases given the supply-chain depth of its ecosystem components; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Typelevel over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-31183CRITICAL fs2 is a compositional, streaming I/O library for Scala. When establishing a server-mode `TLSSocket` using `fs2-io` on Node.js, the parameter `requestCert = true` is ignored, peer | Aug 1, 2022 | 9.8 | 29 | NO | NO |
CVE-2021-39185CRITICAL Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0.22.2, 0.23.0, 0.23.1, and 1.0.0-M1 through 1.0.0-M24, the d | Sep 1, 2021 | 9.1 | 26 | NO | NO |
CVE-2020-5280HIGH http4s before versions 0.18.26, 0.20.20, and 0.21.2 has a local file inclusion vulnerability. This vulnerability applies to all users of org.http4s.server.staticcontent.FileService | Mar 25, 2020 | 7.5 | 26 | NO | NO |
CVE-2025-59822HIGH Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s is vulnerable to HTTP Request Smuggling due to improper hand | Sep 23, 2025 | 7.5 | 25 | NO | NO |
CVE-2022-21653HIGH Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don't override `objectContext()` are vulnerable to | Jan 5, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-21294HIGH Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Http4s before versions 0.21.17, 0.22.0-M2, and 1.0.0-M14 have a vulnerability which can lead | Feb 2, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-21293HIGH blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. All servers running blaze-core before version 0.14.15 are affected by a vulnerability in w | Feb 2, 2021 | 7.5 | 24 | NO | NO |
CVE-2023-22465MEDIUM Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the `User-Agent` and `Server` header pars | Jan 4, 2023 | 5.3 | 20 | NO | NO |
CVE-2021-32643MEDIUM Http4s is a Scala interface for HTTP services. `StaticFile.fromUrl` can leak the presence of a directory on a server when the `URL` scheme is not `file://`, and the URL points to a | May 27, 2021 | 5.8 | 20 | NO | NO |
CVE-2023-50730HIGH Grackle is a GraphQL server written in functional Scala, built on the Typelevel stack. The GraphQL specification requires that GraphQL fragments must not form cycles, either direct | Dec 22, 2023 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Typelevel.
Media articles that mention a CVE ID that affects a product developed by Typelevel — matched by CVE ID, not by vendor name.