Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Org.http4s:http4s blaze server 2.13: blaze: Unbounded WebSocket message aggregation in http4s-blaze-server

0
High
Published: 07/24/2026 (07/24/2026, 22:28:05 UTC)
Source: GCVE Database
Product: org.http4s:http4s-blaze-server_2.13

Description

The http4s-blaze-server aggregates incoming WebSocket message fragments without limiting total size or fragment count. An attacker completing a WebSocket handshake can send an unterminated fragmented message, causing unbounded heap growth in the server JVM and resulting in denial of service via OutOfMemoryError. This affects any http4s application using BlazeServerBuilder for WebSocket routes with versions prior to 0.23.18. No default configuration limits the aggregate buffer size, and the maxWebSocketBufferSize setting only limits individual frames. Mitigation involves limiting or terminating WebSocket traffic at a fronting layer or migrating to a maintained backend, as blaze-server is end-of-life upstream.

CVSS v3.1

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected software

Mavenghsa
org.http4s:http4s-blaze-server_2.13
Affected versions
<0.23.18
Mavenghsa
org.http4s:http4s-blaze-server_2.13
Affected versions
>=1.0.0-M1 <1.0.0-M42
Mavenghsa
org.http4s:http4s-blaze-server_2.12
Affected versions
<0.23.18
Mavenghsa
org.http4s:http4s-blaze-server_3
Affected versions
>=1.0.0-M1 <1.0.0-M42

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/25/2026, 23:50:32 UTC

Technical Analysis

The vulnerability in org.http4s:http4s-blaze-server_2.13 allows unbounded aggregation of fragmented WebSocket messages. Specifically, the server buffers all fragments of an incoming WebSocket message with no limit on total size or fragment count. An attacker can exploit this by sending a fragmented message that never sets the FIN bit, causing the server to buffer fragments indefinitely. This leads to unbounded heap memory growth and eventual JVM OutOfMemoryError, resulting in denial of service. The issue affects all versions prior to 0.23.18. The maxWebSocketBufferSize parameter only limits individual frame sizes and does not mitigate the aggregation issue. No patch is currently available, and the blaze-server backend is end-of-life, with recommendations to migrate to a maintained backend such as ember.

Potential Impact

The vulnerability allows remote unauthenticated attackers (if the WebSocket endpoint is unauthenticated) or authenticated clients (if authentication is required) to cause denial of service by exhausting server heap memory. This results in the termination of the JVM process running the blaze selector thread due to OutOfMemoryError. The impact is high as it disrupts availability of the affected http4s applications serving WebSocket routes over BlazeServerBuilder.

Mitigation Recommendations

No official patch or configuration fix is currently available for this vulnerability. The maxWebSocketBufferSize setting does not mitigate the issue. Recommended mitigations include terminating or limiting WebSocket traffic at a fronting layer that enforces message size and fragment limits, or disabling WebSocket routes entirely. For a longer-term solution, plan migration from the blaze-server backend to a maintained alternative such as ember, as blaze-server is end-of-life upstream.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-7ppr-r889-mcf2
Osv Schema Version
1.4.0
Aliases
[]
Ecosystems
["Maven"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6a65421d9c2644c7f808807d

Added to database: 07/25/2026, 23:09:17 UTC

Last enriched: 07/25/2026, 23:50:32 UTC

Last updated: 07/26/2026, 03:46:49 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses