CVE-2026-73494
- EPSS 0.37%
- Veröffentlicht 14.09.2026 17:33:49
- Zuletzt bearbeitet 30.09.2026 17:51:56
blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.0-M1 until 1.0.0-M42, five HTTP/1.1 conformance laxities in the hand-written Java parser under http/src/main/java/org/http4s/blaze...
CVE-2026-73495
- EPSS 0.29%
- Veröffentlicht 12.08.2026 21:11:55
- Zuletzt bearbeitet 09.09.2026 21:02:22
blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42, blaze-server can merge HTTP/1.1 chunked-body trailer fields into Request.headers. Because trailer fields are attacker-controlled...
CVE-2026-73493
- EPSS 0.35%
- Veröffentlicht 12.08.2026 21:08:34
- Zuletzt bearbeitet 10.09.2026 20:30:11
Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with no limit on total size or fragment count. A client ...