Threats Tagged 'ghsa-7ppr-r889-mcf2'
View all threats tagged with 'ghsa-7ppr-r889-mcf2'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-7ppr-r889-mcf2'
Click on any threat for detailed analysis and mitigation recommendations
Org.http4s:http4s blaze server 2.13: blaze: Unbounded WebSocket message aggregation in http4s-blaze-server 0 The http4s-blaze-server aggregates incoming WebSocket message fragments without limiting total size or fragment count. An attacker completing a WebSocket handshake can send an unterminated fragmented message, causing unbounded heap growth in the server JVM and resulting in denial of service via OutOfMemoryError. This affects any http4s application using BlazeServerBuilder for WebSocket routes with versions prior to 0.23.18. No default configuration limits the aggregate buffer size, and the maxWebSocketBufferSize setting only limits individual frames. Mitigation involves limiting or terminating WebSocket traffic at a fronting layer or migrating to a maintained backend, as blaze-server is end-of-life upstream. Join the discussion | GCVE Database | 07/24/2026, 22:28:05 UTC Added: 07/25/2026, 23:09:17 UTC |
Showing 1 to 1 of 1 result