๐Ÿ” CVE Alert

CVE-2026-73494

HIGH 7.4

blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser

CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
0th

blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.0-M1 until 1.0.0-M42, five HTTP/1.1 conformance laxities in the hand-written Java parser under http/src/main/java/org/http4s/blaze/http/parser/ can cause blaze to derive a different request boundary than a stricter fronting intermediary. A default BlazeServerBuilder accepts invalid or valueless header field names that violate tchar syntax, obsolete folded field lines (obs-fold), unsupported Transfer-Encoding values, duplicate Content-Length fields, and requests containing both Transfer-Encoding and Content-Length. If a lenient or legacy proxy forwards the malformed bytes but interprets them differently, the disagreement can permit front-end authorization bypass, response-queue poisoning on pooled backend connections, or cache poisoning. Exploitation requires a pair of disagreeing parsers; no non-default blaze configuration is required. The affected checks are enforced in BodyAndHeaderParser and Http1ServerParser. This issue is fixed in versions 0.23.18 and 1.0.0-M42.

CWE CWE-444
Vendor http4s
Product blaze
Published Sep 14, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for http4s blaze

Be the first to know when new high vulnerabilities affecting http4s blaze are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

http4s / blaze
< 0.23.18 >= 1.0.0-M1, < 1.0.0-M42
org.http4s / blaze-http_2.13
< 0.23.18 >= 1.0.0-M1, < 1.0.0-M42
org.http4s / blaze-http_3
< 0.23.18 >= 1.0.0-M1, < 1.0.0-M42
org.http4s / http4s-blaze-server_2.13
< 0.23.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/http4s/blaze/security/advisories/GHSA-mhvj-jhpq-885v github.com: https://github.com/http4s/blaze/commit/3f7c022e306631b006dcb43a1d7f65c0d1966f17 github.com: https://github.com/http4s/blaze/commit/4eec2007806aa9acfefb00ebb636ddc39a147a96 github.com: https://github.com/http4s/blaze/commit/927b67753a78c13c4445dac9307f511f5c4878c3 github.com: https://github.com/http4s/blaze/commit/a54bc9cd31758335c7f24e29763622fd03fcf734 github.com: https://github.com/http4s/blaze/commit/c47d9675f87603f11b32a11d503626bdf9be5c7a github.com: https://github.com/http4s/blaze/commit/e871ebb1d27f50c98fd56988526ce42d0fee74d6 github.com: https://github.com/http4s/blaze/releases/tag/v0.23.18 github.com: https://github.com/http4s/blaze/releases/tag/v1.0.0-M42