7.4

CVE-2026-73494

blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser

blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.0-M1 until 1.0.0-M42, five HTTP/1.1 conformance laxities in the hand-written Java parser under http/src/main/java/org/http4s/blaze/http/parser/ can cause blaze to derive a different request boundary than a stricter fronting intermediary. A default BlazeServerBuilder accepts invalid or valueless header field names that violate tchar syntax, obsolete folded field lines (obs-fold), unsupported Transfer-Encoding values, duplicate Content-Length fields, and requests containing both Transfer-Encoding and Content-Length. If a lenient or legacy proxy forwards the malformed bytes but interprets them differently, the disagreement can permit front-end authorization bypass, response-queue poisoning on pooled backend connections, or cache poisoning. Exploitation requires a pair of disagreeing parsers; no non-default blaze configuration is required. The affected checks are enforced in BodyAndHeaderParser and Http1ServerParser. This issue is fixed in versions 0.23.18 and 1.0.0-M42.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerhttp4s
≫
Produkt blaze
Version < 0.23.18
Status affected
Version >= 1.0.0-M1, < 1.0.0-M42
Status affected
Herstellerorg.http4s
≫
Produkt blaze-http_2.13
Version < 0.23.18
Status affected
Version >= 1.0.0-M1, < 1.0.0-M42
Status affected
Herstellerorg.http4s
≫
Produkt blaze-http_3
Version < 0.23.18
Status affected
Version >= 1.0.0-M1, < 1.0.0-M42
Status affected
Herstellerorg.http4s
≫
Produkt http4s-blaze-server_2.13
Version < 0.23.18
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.309
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 7.4 2.2 5.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

https://github.com/http4s/blaze/releases/tag/v0.23.18
https://github.com/http4s/blaze/releases/tag/v1.0.0-M42
https://github.com/http4s/blaze/security/advisories/GHSA-mhvj-jhpq-885v
https://github.com/http4s/blaze/commit/3f7c022e306631b006dcb43a1d7f65c0d1966f17
https://github.com/http4s/blaze/commit/4eec2007806aa9acfefb00ebb636ddc39a147a96
https://github.com/http4s/blaze/commit/927b67753a78c13c4445dac9307f511f5c4878c3
https://github.com/http4s/blaze/commit/a54bc9cd31758335c7f24e29763622fd03fcf734
https://github.com/http4s/blaze/commit/c47d9675f87603f11b32a11d503626bdf9be5c7a
https://github.com/http4s/blaze/commit/e871ebb1d27f50c98fd56988526ce42d0fee74d6