GHSA-mhvj-jhpq-885v

Suggest an improvement
Source
https://github.com/advisories/GHSA-mhvj-jhpq-885v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-mhvj-jhpq-885v/GHSA-mhvj-jhpq-885v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mhvj-jhpq-885v
Aliases
Published
2026-07-24T22:26:27Z
Modified
2026-08-12T21:25:59Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
Details

Summary

Five independent HTTP/1.1 conformance laxities in blaze's hand-written Java parser (http/src/main/java/org/http4s/blaze/http/parser/) cause request-boundary disagreement with a stricter intermediary. All are reachable from a default BlazeServerBuilder with no non-default configuration.

Impact

Actual exploitability depends on the fronting proxy — a boundary disagreement requires a pair of parsers that disagree. Where the proxy forwards the malformed bytes and derives a different message boundary, the consequences are the standard set: front-end ACL/auth bypass, response-queue poisoning on pooled backend connections, and cache poisoning. Risk concentrates on lenient or legacy intermediaries.

Workarounds

Deploy behind an RFC-strict reverse proxy (nginx, HAProxy, Envoy, ALB) that rejects or re-serializes malformed requests at the edge; this neutralizes most of these for deployments that cannot upgrade immediately.

Database specific
{
    "cwe_ids":  [
        "CWE-444"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-24T22:26:27Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

Maven
org.http4s:http4s-blaze-server_2.13

Package

Name
org.http4s:http4s-blaze-server_2.13
View open source insights on deps.dev
Purl
pkg:maven/org.http4s/http4s-blaze-server_2.13

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.23.18

Affected versions

0.*
0.10.0-M10
0.21.0-M1
0.21.0-M2
0.21.0-M3
0.21.0-M4
0.21.0-M5
0.21.0-M6
0.21.0-RC1
0.21.0-RC2
0.21.0-RC3
0.21.0-RC4
0.21.0-RC5
0.21.0
0.21.1
0.21.2
0.21.3
0.21.4
0.21.5
0.21.6
0.21.7
0.21.8
0.21.9
0.21.11
0.21.12
0.21.13
0.21.14
0.21.15
0.21.16
0.21.17
0.21.18
0.21.19
0.21.20
0.21.21
0.21.22
0.21.23
0.21.24
0.21.25
0.21.26
0.21.27
0.21.28
0.21.29
0.21.30
0.21.31
0.21.32
0.21.33
0.21.34
0.22.0-M1
0.22.0-M2
0.22.0-M3
0.22.0-M4
0.22.0-M5
0.22.0-M6
0.22.0-M7
0.22.0-M8
0.22.0-RC1
0.22.0
0.22-53-01128f5
0.22-96-55d3184
0.22-129-24d065b
0.22-143-49b5a8d
0.22.1
0.22.2
0.22.3
0.22.4
0.22.5
0.22.6
0.22.7
0.22.8
0.22.9
0.22.10
0.22.11
0.22.12
0.22.13
0.22.14
0.22.15
0.23.0-M1
0.23.0-RC1
0.23.0
0.23.1
0.23.2
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17

Database specific

last_known_affected_version_range
"<= 0.23.17"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-mhvj-jhpq-885v/GHSA-mhvj-jhpq-885v.json"
org.http4s:blaze-http_2.13

Package

Name
org.http4s:blaze-http_2.13
View open source insights on deps.dev
Purl
pkg:maven/org.http4s/blaze-http_2.13

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.23.18

Affected versions

0.*
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.15.0-M1
0.15.0-M2
0.15.0-M3
0.15.0
0.15.1
0.15.2
0.15.3
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17

Database specific

last_known_affected_version_range
"<= 0.23.17"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-mhvj-jhpq-885v/GHSA-mhvj-jhpq-885v.json"
org.http4s:blaze-http_3

Package

Name
org.http4s:blaze-http_3
View open source insights on deps.dev
Purl
pkg:maven/org.http4s/blaze-http_3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.23.18

Affected versions

0.*
0.15.0
0.15.1
0.15.2
0.15.3
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17

Database specific

last_known_affected_version_range
"<= 0.23.17"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-mhvj-jhpq-885v/GHSA-mhvj-jhpq-885v.json"
org.http4s:blaze-http_3

Package

Name
org.http4s:blaze-http_3
View open source insights on deps.dev
Purl
pkg:maven/org.http4s/blaze-http_3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0-M1
Fixed
1.0.0-M42

Affected versions

1.*
1.0.0-M33
1.0.0-M34
1.0.0-M35
1.0.0-M36
1.0.0-M37
1.0.0-M38
1.0.0-M39
1.0.0-M40
1.0.0-M41

Database specific

last_known_affected_version_range
"<= 1.0.0-M41"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-mhvj-jhpq-885v/GHSA-mhvj-jhpq-885v.json"
org.http4s:blaze-http_2.13

Package

Name
org.http4s:blaze-http_2.13
View open source insights on deps.dev
Purl
pkg:maven/org.http4s/blaze-http_2.13

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0-M1
Fixed
1.0.0-M42

Affected versions

1.*
1.0.0-M33
1.0.0-M34
1.0.0-M35
1.0.0-M36
1.0.0-M37
1.0.0-M38
1.0.0-M39
1.0.0-M40
1.0.0-M41

Database specific

last_known_affected_version_range
"<= 1.0.0-M41"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-mhvj-jhpq-885v/GHSA-mhvj-jhpq-885v.json"