Junglewise Threat Intelligence

CVE-2026-73494: http4s blaze HTTP/1.1 parser conformance bypass

CVE-2026-73494 · Severity: high · CVSS 7.4 · Published 2026-09-14

Vendors: Http4s.

Executive brief

blaze is a Scala library for building asynchronous network applications. The HTTP/1.1 parser accepts malformed HTTP requests that violate standards, potentially allowing attackers to bypass authorization rules, poison response caches, or inject requests on pooled connections when used behind a stricter proxy or intermediary.

Technical details

The hand-written Java parser in blaze (BodyAndHeaderParser and Http1ServerParser) implements five HTTP/1.1 parsing laxities: acceptance of invalid header field names violating tchar syntax, obsolete folded field lines (obs-fold), unsupported Transfer-Encoding values, duplicate Content-Length fields, and requests with both Transfer-Encoding and Content-Length. An attacker can exploit this by sending malformed requests that a lenient blaze parser accepts but a stricter upstream proxy rejects or interprets differently, leading to HTTP request smuggling, cache poisoning, or authorization bypass. The vulnerability requires a pair of disagreeing parsers (blaze and a stricter intermediary); no non-default configuration is needed to trigger it. Patches are available in versions 0.23.18 and 1.0.0-M42.

Affected products

  • http4s blaze < 0.23.18, 1.0.0-M1 through 1.0.0-M41

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Versions 0.23.18 and 1.0.0-M42

References

Related threats