7.5
CVE-2026-73493
- EPSS 0.35%
- Veröffentlicht 12.08.2026 21:08:34
- Zuletzt bearbeitet 13.08.2026 18:18:17
- CVE-Watchlists
- Unerledigt
http4s-blaze-server: Unbounded WebSocket message aggregation
Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with no limit on total size or fragment count. A client that completes a WebSocket handshake can send an unterminated fragmented message and drive unbounded heap growth in the server JVM, resulting in denial of service through OutOfMemoryError. Any http4s application serving WebSocket routes over BlazeServerBuilder is affected, no non-default configuration is required, and maxWebSocketBufferSize does not bound the aggregate because it bounds only individual frames. A single connection sending continuation frames that never set FIN forces the server to buffer every fragment until the heap is exhausted, terminating the JVM with OutOfMemoryError on the blaze selector thread. Small fragments amplify the cost through per-frame object overhead, so a modest volume of wire bytes is sufficient. This issue is fixed in versions 0.23.18 and 1.0.0-M42.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerhttp4s
≫
Produkt
blaze
Version
< 0.23.18
Status
affected
Version
>= 1.0.0-M1, < 1.0.0-M42
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.275 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-770 Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
https://github.com/http4s/blaze/security/advisories/GHSA-7ppr-r889-mcf2
https://github.com/http4s/blaze/commit/173e8ca820a0d12110bfe409c72e9b9c3d28d471
https://github.com/http4s/blaze/releases/tag/v0.23.18
https://github.com/http4s/blaze/releases/tag/v1.0.0-M42