SCA: security update for org.http4s:blaze-core_2.11, org.http4s:blaze-core_2.12, org.http4s:blaze-core_2.13 (GHSA-xmw9-q7x9-j5qc)

high Tenable Cloud Security Plugin ID 420587

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. All servers
running blaze-core before version 0.14.15 are affected by a vulnerability in which unbounded connection
acceptance leads to file handle exhaustion. Blaze, accepts connections unconditionally on a dedicated
thread pool. This has the net effect of amplifying degradation in services that are unable to handle their
current request load, since incoming connections are still accepted and added to an unbounded queue. Each
connection allocates a socket handle, which drains a scarce OS resource. This can also confound higher
level circuit breakers which work based on detecting failed connections. The vast majority of affected
users are using it as part of http4s-blaze-server <= 0.21.16. http4s provides a mechanism for limiting
open connections, but is enforced inside the Blaze accept loop, after the connection is accepted and the
socket opened. Thus, the limit only prevents the number of connections which can be simultaneously
processed, not the number of connections which can be held open. The issue is fixed in version 0.14.15 for
"NIO1SocketServerGroup". A "maxConnections" parameter is added, with a default value of 512. Concurrent
connections beyond this limit are rejected. To run unbounded, which is not recommended, set a negative
number. The "NIO2SocketServerGroup" has no such setting and is now deprecated. There are several possible
workarounds described in the refrenced GitHub Advisory GHSA-xmw9-q7x9-j5qc. (CVE-2021-21293)

See Also

https://github.com/advisories/GHSA-xmw9-q7x9-j5qc

Plugin Details

Severity: High

ID: 420587

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2021-21293

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 2/2/2021

Vulnerability Publication Date: 2/2/2021

Reference Information

CVE: CVE-2021-21293