{"id":"GHSA-46q4-43ph-c6fr","summary":"blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)","details":"### Summary\n  blaze-server can merge HTTP/1.1 chunked-body trailer fields into `Request.headers`. Because trailer fields are attacker-controlled, an unauthenticated remote client can inject arbitrary header names/values (e.g. `X-Forwarded-For`, internal-auth headers) that a fronting proxy sanitized from the request-header section, bypassing header-based trust decisions in the application.\n\n  ### Impact\n  Any http4s application using `BlazeServerBuilder` over HTTP/1.1 whose routes or middleware trust proxy-set headers (e.g., `X-Forwarded-For`, `X-Real-IP`, `X-Forwarded-Host`, org-internal auth headers) is affected. Where a fronting proxy strips/normalizes those headers but forwards chunked bodies with trailers intact, an attacker can spoof client IP for allow-lists/rate-limits/audit, forge the `https` scheme, or inject internal-auth headers. A promoted `Connection: close` trailer is also honored, allowing attacker-controlled termination of pooled backend connections.\n\n  ### Workarounds\n  Deploy behind a proxy that removes trailer fields (or rejects requests that use trailers) before forwarding; until patched, avoid trust decisions based on headers that a proxy is relied upon to sanitize.","aliases":["CVE-2026-73495"],"modified":"2026-08-12T21:25:59.135045Z","published":"2026-07-24T22:26:48Z","database_specific":{"github_reviewed_at":"2026-07-24T22:26:48Z","nvd_published_at":null,"cwe_ids":["CWE-444"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/http4s/blaze/security/advisories/GHSA-46q4-43ph-c6fr"},{"type":"WEB","url":"https://github.com/http4s/blaze/commit/ef3e666c146cfc16cb6603f1fc3c464daab4a24f"},{"type":"PACKAGE","url":"https://github.com/http4s/blaze"},{"type":"WEB","url":"https://github.com/http4s/blaze/releases/tag/v0.23.18"},{"type":"WEB","url":"https://github.com/http4s/blaze/releases/tag/v1.0.0-M42"}],"affected":[{"package":{"name":"org.http4s:blaze-http_2.13","ecosystem":"Maven","purl":"pkg:maven/org.http4s/blaze-http_2.13"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.23.18"}]}],"versions":["0.14.10","0.14.11","0.14.12","0.14.13","0.14.14","0.14.15","0.14.16","0.14.17","0.14.18","0.14.5","0.14.6","0.14.7","0.14.8","0.14.9","0.15.0","0.15.0-M1","0.15.0-M2","0.15.0-M3","0.15.1","0.15.2","0.15.3","0.23.12","0.23.13","0.23.14","0.23.15","0.23.16","0.23.17"],"database_specific":{"last_known_affected_version_range":"\u003c= 0.23.17","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-46q4-43ph-c6fr/GHSA-46q4-43ph-c6fr.json"}},{"package":{"name":"org.http4s:blaze-http_2.12","ecosystem":"Maven","purl":"pkg:maven/org.http4s/blaze-http_2.12"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.23.18"}]}],"versions":["0.12.10","0.12.11","0.12.12","0.12.13","0.12.4","0.12.5","0.12.6","0.12.7","0.12.8","0.12.9","0.13.0","0.14.0","0.14.0-M1","0.14.0-M10","0.14.0-M11","0.14.0-M12","0.14.0-M2","0.14.0-M3","0.14.0-M4","0.14.0-M5","0.14.0-M6","0.14.0-M7","0.14.0-M8","0.14.0-M9","0.14.0-RC1","0.14.1","0.14.10","0.14.11","0.14.12","0.14.13","0.14.14","0.14.15","0.14.16","0.14.17","0.14.18","0.14.2","0.14.3","0.14.4","0.14.5","0.14.6","0.14.7","0.14.8","0.14.9","0.15.0","0.15.0-M1","0.15.0-M2","0.15.0-M3","0.15.1","0.15.2","0.15.3","0.23.12","0.23.13","0.23.14","0.23.15","0.23.16","0.23.17"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-46q4-43ph-c6fr/GHSA-46q4-43ph-c6fr.json","last_known_affected_version_range":"\u003c= 0.23.17"}},{"package":{"name":"org.http4s:blaze-http_3","ecosystem":"Maven","purl":"pkg:maven/org.http4s/blaze-http_3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.23.18"}]}],"versions":["0.15.0","0.15.1","0.15.2","0.15.3","0.23.12","0.23.13","0.23.14","0.23.15","0.23.16","0.23.17"],"database_specific":{"last_known_affected_version_range":"\u003c= 0.23.17","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-46q4-43ph-c6fr/GHSA-46q4-43ph-c6fr.json"}},{"package":{"name":"org.http4s:blaze-http_3","ecosystem":"Maven","purl":"pkg:maven/org.http4s/blaze-http_3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0-M1"},{"fixed":"1.0.0-M42"}]}],"versions":["1.0.0-M33","1.0.0-M34","1.0.0-M35","1.0.0-M36","1.0.0-M37","1.0.0-M38","1.0.0-M39","1.0.0-M40","1.0.0-M41"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-46q4-43ph-c6fr/GHSA-46q4-43ph-c6fr.json"}},{"package":{"name":"org.http4s:blaze-http_2.13","ecosystem":"Maven","purl":"pkg:maven/org.http4s/blaze-http_2.13"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0-M1"},{"fixed":"1.0.0-M42"}]}],"versions":["1.0.0-M33","1.0.0-M34","1.0.0-M35","1.0.0-M36","1.0.0-M37","1.0.0-M38","1.0.0-M39","1.0.0-M40","1.0.0-M41"],"database_specific":{"last_known_affected_version_range":"\u003c= 1.0.0-M41","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-46q4-43ph-c6fr/GHSA-46q4-43ph-c6fr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}