Description
blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.0-M1 until 1.0.0-M42, five HTTP/1.1 conformance laxities in the hand-written Java parser under http/src/main/java/org/http4s/blaze/http/parser/ can cause blaze to derive a different request boundary than a stricter fronting intermediary. A default BlazeServerBuilder accepts invalid or valueless header field names that violate tchar syntax, obsolete folded field lines (obs-fold), unsupported Transfer-Encoding values, duplicate Content-Length fields, and requests containing both Transfer-Encoding and Content-Length. If a lenient or legacy proxy forwards the malformed bytes but interprets them differently, the disagreement can permit front-end authorization bypass, response-queue poisoning on pooled backend connections, or cache poisoning. Exploitation requires a pair of disagreeing parsers; no non-default blaze configuration is required. The affected checks are enforced in BodyAndHeaderParser and Http1ServerParser. This issue is fixed in versions 0.23.18 and 1.0.0-M42.
Published: 2026-09-14
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: HTTP Request Smuggling
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in the Blaze Scala library’s hand‑written Java HTTP/1.1 parser. Five conformance laxities expose Blaze to parse request boundaries differently from upstream proxies or other intermediaries. When a request contains header fields with invalid tchar syntax, obsolete folded lines, unsupported Transfer‑Encoding values, duplicate Content‑Length fields, or both Transfer‑Encoding and Content‑Length, Blaze accepts them while a stricter front‑end may reject or interpret them differently. This mismatch permits request smuggling, which can lead to front‑end authorization bypass, response‑queue poisoning on pooled backend connections, or cache poisoning. The issue is classified as CWE‑444, reflecting improper input validation in an otherwise performance‑directed parser.

Affected Systems

The flaw affects every release of the Blaze HTTP server library earlier than version 0.23.18 and all milestone releases from 1.0.0-M1 through 1.0.0-M42. The affected packages are blaze-http_2.13, org.http4s:blaze-http_3, org.http4s:http4s-blaze-server_2.13, and http4s:blaze. It is triggered only when the default BlazeServerBuilder is used with permissive header handling; no proprietary configuration changes are required.

Risk and Exploitability

The vulnerability has a CVSS base score of 7.4, indicating high severity. The EPSS score of <1% indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a pair of parsers that disagree on request boundary interpretation—typically an upstream proxy or load balancer versus the Blaze backend. Attackers with network access to the front‑end can craft malformed headers to trigger the backend into misinterpreting the request, thereby enabling HTTP request smuggling that can lead to front‑end authorization bypass, response‑queue poisoning on pooled backend connections, or cache poisoning.

Generated by OpenCVE AI on September 21, 2026 at 00:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Blaze library to at least version 0.23.18 or 1.0.0-M42.
  • Reconfigure BlazeServerBuilder to enforce strict header validation, rejecting malformed tchar syntax, obsolete folded lines, duplicate Content‑Length fields, and conflicting Transfer‑Encoding/Content‑Length values.
  • Ensure upstream proxies, load balancers, or gateways use strict HTTP/1.1 parsing and forward requests unchanged, or replace them with strictly compliant components.

Generated by OpenCVE AI on September 21, 2026 at 00:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-mhvj-jhpq-885v blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
History

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.0-M1 until 1.0.0-M42, five HTTP/1.1 conformance laxities in the hand-written Java parser under http/src/main/java/org/http4s/blaze/http/parser/ can cause blaze to derive a different request boundary than a stricter fronting intermediary. A default BlazeServerBuilder accepts invalid or valueless header field names that violate tchar syntax, obsolete folded field lines (obs-fold), unsupported Transfer-Encoding values, duplicate Content-Length fields, and requests containing both Transfer-Encoding and Content-Length. If a lenient or legacy proxy forwards the malformed bytes but interprets them differently, the disagreement can permit front-end authorization bypass, response-queue poisoning on pooled backend connections, or cache poisoning. Exploitation requires a pair of disagreeing parsers; no non-default blaze configuration is required. The affected checks are enforced in BodyAndHeaderParser and Http1ServerParser. This issue is fixed in versions 0.23.18 and 1.0.0-M42.
Title blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
Weaknesses CWE-444
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T20:05:52.181Z

Reserved: 2026-08-12T19:00:33.735Z

Link: CVE-2026-73494

cve-icon Vulnrichment

Updated: 2026-09-14T19:21:22.363Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:19:58.857

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-73494

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:30:06Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')