Executive brief
blaze is a Scala networking library used by http4s applications to handle HTTP requests. A vulnerability in its HTTP/1.1 parser allows attackers to inject arbitrary headers via chunked transfer encoding trailers, bypassing proxy header filtering and enabling IP spoofing, authorization bypass, or connection termination. Applications behind proxies that strip or validate headers are at risk.
Technical details
blaze-server's HTTP/1.1 parser improperly merges trailer fields from chunked request bodies into Request.headers, treating them as regular request headers. Because trailers are attacker-controlled and arrive after proxy filtering, a remote unauthenticated client can inject headers like X-Forwarded-For, X-Real-IP, X-Forwarded-Host, or internal authorization headers that a fronting proxy has sanitized from the initial request. The parser also honors a malicious Connection: close trailer, allowing attacker-controlled termination of pooled backend connections. The vulnerability affects http4s applications using BlazeServerBuilder over HTTP/1.1 whose routes trust proxy-set headers. The fix routes trailer fields to a separate buffer instead of merging them into Request.headers, and is available in blaze 0.23.18 and 1.0.0-M42.
Affected products
- http4s blaze before 0.23.18 and before 1.0.0-M42
Timeline
- 2026-08-12: disclosed: Published on NVD