Junglewise Threat Intelligence

CVE-2026-73495: http4s blaze HTTP/1.1 trailer header injection

CVE-2026-73495 · Severity: high · CVSS 7.4 · Published 2026-08-12

Vendors: Http4s.

Executive brief

blaze is a Scala networking library used by http4s applications to handle HTTP requests. A vulnerability in its HTTP/1.1 parser allows attackers to inject arbitrary headers via chunked transfer encoding trailers, bypassing proxy header filtering and enabling IP spoofing, authorization bypass, or connection termination. Applications behind proxies that strip or validate headers are at risk.

Technical details

blaze-server's HTTP/1.1 parser improperly merges trailer fields from chunked request bodies into Request.headers, treating them as regular request headers. Because trailers are attacker-controlled and arrive after proxy filtering, a remote unauthenticated client can inject headers like X-Forwarded-For, X-Real-IP, X-Forwarded-Host, or internal authorization headers that a fronting proxy has sanitized from the initial request. The parser also honors a malicious Connection: close trailer, allowing attacker-controlled termination of pooled backend connections. The vulnerability affects http4s applications using BlazeServerBuilder over HTTP/1.1 whose routes trust proxy-set headers. The fix routes trailer fields to a separate buffer instead of merging them into Request.headers, and is available in blaze 0.23.18 and 1.0.0-M42.

Affected products

  • http4s blaze before 0.23.18 and before 1.0.0-M42

Timeline

  • 2026-08-12: disclosed: Published on NVD

References

Related threats