Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Org.http4s:blaze http 2.13: blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)

0
High
Published: 07/24/2026 (07/24/2026, 22:26:48 UTC)
Source: GCVE Database
Product: org.http4s:blaze-http_2.13

Description

A vulnerability in org.http4s blaze-server allows HTTP/1.1 chunked-body trailer fields to be merged into Request.headers. This enables an unauthenticated remote attacker to inject arbitrary HTTP headers that may bypass fronting proxy sanitization. Applications trusting proxy-set headers such as X-Forwarded-For or internal authentication headers are at risk of spoofing client IPs, forging HTTPS schemes, or injecting unauthorized headers. The vulnerability also allows attacker-controlled termination of pooled backend connections via a promoted Connection: close trailer. Workarounds include deploying behind proxies that remove or reject trailer fields and avoiding trust decisions based on proxy-sanitized headers until patched.

CVSS v3.1

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected software

Mavenghsa
org.http4s:blaze-http_2.13
Affected versions
<0.23.18
Mavenghsa
org.http4s:blaze-http_2.12
Affected versions
<0.23.18
Mavenghsa
org.http4s:blaze-http_3
Affected versions
<0.23.18
Mavenghsa
org.http4s:blaze-http_3
Affected versions
>=1.0.0-M1 <1.0.0-M42
Mavenghsa
org.http4s:blaze-http_2.13
Affected versions
>=1.0.0-M1 <1.0.0-M42

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/25/2026, 23:50:40 UTC

Technical Analysis

The blaze-server component of org.http4s (version <0.23.18) merges HTTP/1.1 chunked-body trailer fields into the Request.headers object. Since trailer fields are attacker-controlled, this behavior allows an unauthenticated remote client to inject arbitrary headers that a fronting proxy may have sanitized from the initial request headers. This bypasses header-based trust decisions in applications, affecting any http4s application using BlazeServerBuilder over HTTP/1.1 that relies on proxy-set headers for security decisions. The vulnerability can be exploited to spoof client IP addresses, forge HTTPS schemes, inject internal authentication headers, and prematurely close backend connections. No official patch or fix link is provided in the data, and the vulnerability is classified as high severity with CVSS 3.1 vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N.

Potential Impact

Applications using vulnerable versions of blaze-server that trust proxy-set headers can have their security controls bypassed. Attackers can inject arbitrary headers to spoof client IPs, bypass allow-lists or rate limits, forge HTTPS scheme indicators, inject internal authentication headers, and cause premature termination of backend connections. This compromises confidentiality and integrity of the application’s trust decisions based on HTTP headers. Availability impact is not indicated.

Mitigation Recommendations

No official patch or fix is currently confirmed. Until a patch is available, deploy the application behind a proxy that removes or rejects HTTP/1.1 chunked-body trailer fields before forwarding requests. Additionally, avoid making trust decisions based on headers that rely on proxy sanitization, such as X-Forwarded-For or internal authentication headers. Monitor vendor advisories for updates regarding official fixes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-46q4-43ph-c6fr
Osv Schema Version
1.4.0
Aliases
[]
Ecosystems
["Maven"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6a65421d9c2644c7f8088086

Added to database: 07/25/2026, 23:09:17 UTC

Last enriched: 07/25/2026, 23:50:40 UTC

Last updated: 07/26/2026, 05:29:21 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses