{"id":"CVE-2026-73494","summary":"blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser","details":"blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.0-M1 until 1.0.0-M42, five HTTP/1.1 conformance laxities in the hand-written Java parser under http/src/main/java/org/http4s/blaze/http/parser/ can cause blaze to derive a different request boundary than a stricter fronting intermediary. A default BlazeServerBuilder accepts invalid or valueless header field names that violate tchar syntax, obsolete folded field lines (obs-fold), unsupported Transfer-Encoding values, duplicate Content-Length fields, and requests containing both Transfer-Encoding and Content-Length. If a lenient or legacy proxy forwards the malformed bytes but interprets them differently, the disagreement can permit front-end authorization bypass, response-queue poisoning on pooled backend connections, or cache poisoning. Exploitation requires a pair of disagreeing parsers; no non-default blaze configuration is required. The affected checks are enforced in BodyAndHeaderParser and Http1ServerParser. This issue is fixed in versions 0.23.18 and 1.0.0-M42.","aliases":["GHSA-mhvj-jhpq-885v"],"modified":"2026-09-16T08:05:21.112096Z","published":"2026-09-14T17:33:49.671Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73494.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-444"]},"references":[{"type":"WEB","url":"https://github.com/http4s/blaze/releases/tag/v0.23.18"},{"type":"WEB","url":"https://github.com/http4s/blaze/releases/tag/v1.0.0-M42"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73494.json"},{"type":"ADVISORY","url":"https://github.com/http4s/blaze/security/advisories/GHSA-mhvj-jhpq-885v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73494"},{"type":"FIX","url":"https://github.com/http4s/blaze/commit/3f7c022e306631b006dcb43a1d7f65c0d1966f17"},{"type":"FIX","url":"https://github.com/http4s/blaze/commit/4eec2007806aa9acfefb00ebb636ddc39a147a96"},{"type":"FIX","url":"https://github.com/http4s/blaze/commit/927b67753a78c13c4445dac9307f511f5c4878c3"},{"type":"FIX","url":"https://github.com/http4s/blaze/commit/a54bc9cd31758335c7f24e29763622fd03fcf734"},{"type":"FIX","url":"https://github.com/http4s/blaze/commit/c47d9675f87603f11b32a11d503626bdf9be5c7a"},{"type":"FIX","url":"https://github.com/http4s/blaze/commit/e871ebb1d27f50c98fd56988526ce42d0fee74d6"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/http4s/blaze","events":[{"introduced":"0"},{"fixed":"2ae13a74d55209b6573d5228d1aa94f0361a75d0"},{"fixed":"b2cb8e8591391409bb1df242b45433891251b1b1"},{"fixed":"3f7c022e306631b006dcb43a1d7f65c0d1966f17"},{"fixed":"4eec2007806aa9acfefb00ebb636ddc39a147a96"},{"fixed":"927b67753a78c13c4445dac9307f511f5c4878c3"},{"fixed":"a54bc9cd31758335c7f24e29763622fd03fcf734"},{"fixed":"c47d9675f87603f11b32a11d503626bdf9be5c7a"},{"fixed":"e871ebb1d27f50c98fd56988526ce42d0fee74d6"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.23.18"},{"introduced":"1.0.0-M1"},{"fixed":"1.0.0-M42"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v1.0.0-M41","v0.23.17","v1.0.0-M40","v0.23.16","v1.0.0-M39","v0.23.15","v0.23.14","v1.0.0-M38","v1.0.0-M37","v0.23.13","v1.0.0-M36","v1.0.0-M35","v1.0.0-M34","v1.0.0-M33","v0.23.12","v0.15.3","v0.15.2","v0.15.1","v0.15.0","v0.15.0-M4","v0.15.0-M3","v0.15.0-M2","v0.15.0-M1","v0.14.14","v0.14.13","v0.14.12","v0.14.10","v0.14.8","v0.14.7","v0.14.6","v0.14.5","v0.14.4","v0.14.2","v0.14.0","v0.14.0-M12","v0.14.0-M11","v0.14.0-M10","v0.14.0-M9","v0.14.0-M7","v0.14.0-M3","v0.14.0-M2","v0.13.0","v0.12.0","v0.11.0","v0.10.0","v0.9.0","v0.8.1","v0.8.0","v0.7.0","v0.6.0","v0.5.0","v0.4.0","v0.3.0","v0.2.0","v0.1.0"],"database_specific":{"vanir_signatures":[{"digest":{"threshold":0.9,"line_hashes":["40780726997125153208391369462960998917","242812349689475726822399330906770910858","70956982936300060267393980858160009430","111437233426961614431359773979922698748","251724075645085401740427755264252811359","165761697733828427217073585895701290717","308475171800077332652528308187325174200"]},"id":"CVE-2026-73494-171b7cf9","signature_type":"Line","signature_version":"v1","source":"https://github.com/http4s/blaze/commit/c47d9675f87603f11b32a11d503626bdf9be5c7a","target":{"file":"http/src/main/java/org/http4s/blaze/http/parser/BodyAndHeaderParser.java"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["22184276525989860872859148880995011642","323623036946647435836580242167437765016","55707551053160098211852378271695241744","15646931023564835669520570217542624412","105382022132540860448716843665073204740","43277242895003521266336340615492423745","220530237189192347367460936796940977527","209848481673470596394965632751203575257","184873843172928549940415281132936766033","65103484357875564691602469124775693817","298403257587208400508385769357857292407","84709101680844855806460821226581833832","191757720919609974869905681564257594454","281719494390769075512278434018452488407"],"threshold":0.9},"id":"CVE-2026-73494-4aa645a4","signature_type":"Line","signature_version":"v1","source":"https://github.com/http4s/blaze/commit/4eec2007806aa9acfefb00ebb636ddc39a147a96","target":{"file":"http/src/main/java/org/http4s/blaze/http/parser/BodyAndHeaderParser.java"}},{"deprecated":false,"digest":{"function_hash":"97266908080294769383345854682979683919","length":2645},"id":"CVE-2026-73494-9cd081a0","signature_type":"Function","signature_version":"v1","source":"https://github.com/http4s/blaze/commit/4eec2007806aa9acfefb00ebb636ddc39a147a96","target":{"file":"http/src/main/java/org/http4s/blaze/http/parser/BodyAndHeaderParser.java","function":"parseHeaders"}},{"deprecated":false,"digest":{"function_hash":"153646318109104197098759213324226770001","length":2695},"id":"CVE-2026-73494-c18a7309","signature_type":"Function","signature_version":"v1","source":"https://github.com/http4s/blaze/commit/c47d9675f87603f11b32a11d503626bdf9be5c7a","target":{"file":"http/src/main/java/org/http4s/blaze/http/parser/BodyAndHeaderParser.java","function":"parseHeaders"}},{"source":"https://github.com/http4s/blaze/commit/4eec2007806aa9acfefb00ebb636ddc39a147a96","target":{"file":"http/src/main/java/org/http4s/blaze/http/parser/HttpTokens.java"},"deprecated":false,"digest":{"line_hashes":["11737987260535163784604846195929233277","219085939621185996103596451520496958704"],"threshold":0.9},"id":"CVE-2026-73494-c7959143","signature_type":"Line","signature_version":"v1"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73494.json","vanir_signatures_modified":"2026-09-16T08:05:21Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}