SCA: security update for org.http4s:http4s-blaze-server_2.12, org.http4s:http4s-blaze-server_2.13 (GHSA-xhv5-w9c5-2r2w)

high Tenable Cloud Security Plugin ID 420532

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Http4s before
versions 0.21.17, 0.22.0-M2, and 1.0.0-M14 have a vulnerability which can lead to a denial-of-service.
Blaze-core, a library underlying http4s-blaze-server, accepts connections unboundedly on its selector
pool. This has the net effect of amplifying degradation in services that are unable to handle their
current request load, since incoming connections are still accepted and added to an unbounded queue. Each
connection allocates a socket handle, which drains a scarce OS resource. This can also confound higher
level circuit breakers which work based on detecting failed connections. http4s provides a general
"MaxActiveRequests" middleware mechanism for limiting open connections, but it is enforced inside the
Blaze accept loop, after the connection is accepted and the socket opened. Thus, the limit only prevents
the number of connections which can be simultaneously processed, not the number of connections which can
be held open. In 0.21.17, 0.22.0-M2, and 1.0.0-M14, a new "maxConnections" property, with a default value
of 1024, has been added to the `BlazeServerBuilder`. Setting the value to a negative number restores
unbounded behavior, but is strongly disrecommended. The NIO2 backend does not respect `maxConnections`.
Its use is now deprecated in http4s-0.21, and the option is removed altogether starting in http4s-0.22.
There are several possible workarounds described in the refrenced GitHub Advisory GHSA-xhv5-w9c5-2r2w.
(CVE-2021-21294)

See Also

https://github.com/advisories/GHSA-xhv5-w9c5-2r2w

Plugin Details

Severity: High

ID: 420532

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2021-21294

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 2/2/2021

Vulnerability Publication Date: 2/2/2021

Reference Information

CVE: CVE-2021-21294